CVE-2024-45848

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Sep 12, 2024
Updated: Sep 16, 2024
CWE ID 94
CWE ID 95

Summary

CVE-2024-45848 describes an arbitrary code execution vulnerability affecting MindsDB platform versions 23.12.4.0 through 24.7.4.1 when the ChromaDB integration is utilized. This vulnerability allows attackers to execute Python code on the server through specially crafted ‘INSERT’ queries sent to a ChromaDB database, posing a high risk to both confidentiality and integrity of the system. The attack requires low privileges and no user interaction, making it accessible via network attacks, with a CVSS base score of 8.8 indicating its severity. Organizations using the affected versions are advised to apply patches or updates provided by MindsDB to mitigate this risk effectively. Failure to address this vulnerability could lead to significant security breaches and unauthorized access within the organization’s systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share