Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2024-24759

Description

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service. Version 23.12.4.2 contains a patch.

POC

Reference

- https://github.com/mindsdb/mindsdb/security/advisories/GHSA-4jcv-vp96-94xr

Github

- https://github.com/20142995/nuclei-templates

- https://github.com/ARPSyndicate/cve-scores

- https://github.com/Sim4n6/Sim4n6

- https://github.com/cyb3r-w0lf/nuclei-template-collection

- https://github.com/fkie-cad/nvd-json-data-feeds