CVE-2024-45849

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Sep 12, 2024
Updated: Sep 16, 2024
CWE ID 94
CWE ID 95

Summary

CVE-2024-45849 is an arbitrary code execution vulnerability affecting MindsDB platform versions from 23.10.5.0 to 24.7.4.1, specifically when the Microsoft SharePoint integration is installed. This vulnerability allows an attacker to craft an ‘INSERT’ query containing malicious Python code that, when executed against a database utilizing the SharePoint engine, can be passed to the eval function for execution on the server. The potential risk to organizations includes high integrity and confidentiality impacts, as well as availability issues, with a CVSS base score of 8.8 categorized as HIGH severity and low privileges required for exploitation. To remediate this vulnerability, organizations should upgrade their MindsDB installations to versions that address this issue and review their database queries for potential injection risks. Further information can be found in security advisories related to the vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share