CVE-2024-45852
EUVD-2024-011012.09.2024, 13:15
Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mindsdb | mindsdb | * < 𝑥 < * |
| mindsdb | mindsdb | 23.3.2.0 ≤ |
𝑥
= Vulnerable software versions
Common Weakness Enumeration