CVE-2023-49795

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
11/12/2023
Last modified:
14/12/2023

Description

MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a server-side request forgery vulnerability in `file.py`. This can lead to limited information disclosure. Users should use MindsDB&amp;#39;s `staging` branch or v23.11.4.1, which contain a fix for the issue.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mindsdb:mindsdb:*:*:*:*:*:*:*:* 23.11.4.1 (excluding)