Record summary

EIP currently links 1 Nuclei template to CVE-2024-24759.

Description

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service. Version 23.12.4.2 contains a patch.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 5, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unknown

CVE ListBefore 23.12.4.2affected
< 23.12.4.2affected
GitHub AdvisoryBefore 23.12.4.2 · Fixed in 23.12.4.2affected

Nuclei templates

1
ProjectDiscoveryHIGHMindsDB -DNS Rebinding SSRF Protection BypassCVSS 9.1

Detects DNS rebinding vulnerability that allows bypass of SSRF protection. The vulnerability exists in the URL validation mechanism where DNS resolution is performed without considering DNS rebinding attacks.

Impact

SSRF Protection Bypass via DNS Rebinding

Remediation

Upgrade to mindsdb version 23.12.4.2 or later

WeaknessesCWE-918
AuthorsLee Changhyun(eeche)
Template tagscvecve2024mindsdbssrfdns-rebindingoastvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CPE: cpe:2.3:a:mindsdb:mindsdb:*:*:*:*:*:*:*:*
Shodan: title:"mindsdb"

Source: ProjectDiscovery

References

4