CVE-2024-24759
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service. Version 23.12.4.2 contains a patch.
- Affected products
- Mindsdb
- Mindsdb
- < 23.12.4.2
- Fix
- Available
- CVSS 3.1
- 9.3 CRITICAL
- EPSS
- 4.9% (92th percentile)
- Weakness
- CWE-918
- NVD status
- Analyzed
- Published
- 2024-09-05
CVE-2024-24759 at NVD
No indexed exploits for CVE-2024-24759 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-24759 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.