CVE-2024-24759
MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding
Record summary
EIP currently links 1 Nuclei template to CVE-2024-24759.
Description
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service. Version 23.12.4.2 contains a patch.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 5, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
mindsdbBrowse mindsdb / mindsdbDefault status: unknown | CVE List | Before 23.12.4.2 | affected |
| < 23.12.4.2 | affected | ||
mindsdbBrowse PyPI / mindsdb | GitHub Advisory | Before 23.12.4.2 · Fixed in 23.12.4.2 | affected |
Nuclei templates
1ProjectDiscoveryHIGHMindsDB -DNS Rebinding SSRF Protection BypassCVSS 9.1
Detects DNS rebinding vulnerability that allows bypass of SSRF protection. The vulnerability exists in the URL validation mechanism where DNS resolution is performed without considering DNS rebinding attacks.
Impact
SSRF Protection Bypass via DNS Rebinding
Remediation
Upgrade to mindsdb version 23.12.4.2 or later
Source: ProjectDiscovery