CVE-2023-38699

MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource. Prior to version 23.7.4.0, a call to requests with `verify=False` disables SSL certificate checks. This rule enforces always verifying SSL certificates for methods in the Requests library. In version 23.7.4.0, certificates are validated by default, which is the desired behavior.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mindsdb:mindsdb:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:14

Type Values Removed Values Added
Summary
  • (es) AI Virtual Database de MindsDB permite a los desarrolladores conectar cualquier modelo AI/ML a cualquier fuente de datos. Antes de la versión 23.7.4.0, una llamada a requests con `verify=False` deshabilitaba la comprobación de certificados SSL. Esta regla obliga a comprobar siempre los certificados SSL de los métodos de la biblioteca de peticiones. En la versión 23.7.4.0, los certificados se validan por defecto, que es el comportamiento deseado.
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 9.1
References () https://github.com/mindsdb/mindsdb/commit/083afcf6567cf51aa7d89ea892fd97689919053b - Patch () https://github.com/mindsdb/mindsdb/commit/083afcf6567cf51aa7d89ea892fd97689919053b - Patch
References () https://github.com/mindsdb/mindsdb/releases/tag/v23.7.4.0 - Release Notes () https://github.com/mindsdb/mindsdb/releases/tag/v23.7.4.0 - Release Notes
References () https://github.com/mindsdb/mindsdb/security/advisories/GHSA-8hx6-qv6f-xgcw - Vendor Advisory () https://github.com/mindsdb/mindsdb/security/advisories/GHSA-8hx6-qv6f-xgcw - Vendor Advisory

Information

Published : 2023-08-04 18:15

Updated : 2024-11-21 08:14


NVD link : CVE-2023-38699

Mitre link : CVE-2023-38699

CVE.ORG link : CVE-2023-38699


JSON object : View

Products Affected

mindsdb

  • mindsdb
CWE
CWE-311

Missing Encryption of Sensitive Data