216.73.216.6

CVE-2024-45851

· Published 12/09/2024 13:15 · Modified 16/09/2024 17:36

Labels: CVE-2024-45851 2024-09-126f8de1f0-f67e-45a6-b68f-98777fdb759cCVE-2024-45851CWE-94CWE-95

Essential information

Published
12/09/2024 13:15
Modified
16/09/2024 17:36
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, an ‘INSERT’ query can be used for list item creation. If such a query is specially crafted to contain Python code and is run against the database, the code will be passed to an eval function and executed on the server.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
6f8de1f0-f67e-45a6-b68f-98777fdb759c
NVD
View on NVD

Affected products (CPE)

ProductCPE
mindsdb / mindsdb cpe:2.3:a:mindsdb:mindsdb:*:*:*:*:*:*:*:*

References