Vulnerabilities > Mindsdb > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-09-12 | CVE-2024-45846 | Code Injection vulnerability in Mindsdb An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is installed on the server. | 8.8 |
2024-09-12 | CVE-2024-45847 | Code Injection vulnerability in Mindsdb An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrations is installed on the server. | 8.8 |
2024-09-12 | CVE-2024-45848 | Code Injection vulnerability in Mindsdb 23.12.4.0/23.12.4.1 An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is installed on the server. | 8.8 |
2024-09-12 | CVE-2024-45849 | Code Injection vulnerability in Mindsdb An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. | 8.8 |
2024-09-12 | CVE-2024-45850 | Code Injection vulnerability in Mindsdb An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. | 8.8 |
2024-09-12 | CVE-2024-45851 | Code Injection vulnerability in Mindsdb An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. | 8.8 |
2024-09-12 | CVE-2024-45852 | Deserialization of Untrusted Data vulnerability in Mindsdb Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with. | 8.8 |
2024-09-12 | CVE-2024-45853 | Deserialization of Untrusted Data vulnerability in Mindsdb Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when used for a prediction. | 7.5 |
2024-09-12 | CVE-2024-45854 | Deserialization of Untrusted Data vulnerability in Mindsdb Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when a ‘describe’ query is run on it. | 7.5 |
2024-09-12 | CVE-2024-45855 | Deserialization of Untrusted Data vulnerability in Mindsdb Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when using ‘finetune’ on it. | 7.5 |