CVE-2024-45854
12.09.2024, 13:15
Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded inhouse model to run arbitrary code on the server when a describe query is run on it.Enginsight
Vendor | Product | Version |
---|---|---|
mindsdb | mindsdb | * < 𝑥 < * |
mindsdb | mindsdb | 23.10.3.0 ≤ |
𝑥
= Vulnerable software versions
Common Weakness Enumeration