CVE-2024-45855
EUVD-2024-011312.09.2024, 13:15
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when using ‘finetune’ on it.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mindsdb | mindsdb | 23.10.2.0 ≤ |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| mindsdb | mindsdb | 23.10.2.0 ≤ 𝑥 < * | ADP |
Common Weakness Enumeration