icon

We found results for “

CVE-2024-24759

Good to know:

icon
icon

Date: September 5, 2024

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service. Version 23.12.4.2 contains a patch.

Language: Python

Severity Score

Severity Score

Weakness Type (CWE)

Server-Side Request Forgery (SSRF)

CWE-918

Reliance on Reverse DNS Resolution for a Security-Critical Action

CWE-350

Top Fix

icon

Upgrade Version

Upgrade to version mindsdb - 23.12.4.2

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): CHANGED
Confidentiality (C): HIGH
Integrity (I): NONE
Availability (A): LOW

Do you need more information?

Contact Us