CVE-2023-38699
04.08.2023, 18:15
MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource. Prior to version 23.7.4.0, a call to requests with `verify=False` disables SSL certificate checks. This rule enforces always verifying SSL certificates for methods in the Requests library. In version 23.7.4.0, certificates are validated by default, which is the desired behavior.Enginsight
| Vendor | Product | Version |
|---|---|---|
| mindsdb | mindsdb | 𝑥 < 23.7.4.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References