CVE-2023-38699
MindsDB 'Call to requests with verify=False disabling SSL certificate checks, security issue.' issue
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource. Prior to version 23.7.4.0, a call to requests with `verify=False` disables SSL certificate checks. This rule enforces always verifying SSL certificates for methods in the Requests library. In version 23.7.4.0, certificates are validated by default, which is the desired behavior.
AI Virtual Database de MindsDB permite a los desarrolladores conectar cualquier modelo AI/ML a cualquier fuente de datos. Antes de la versión 23.7.4.0, una llamada a requests con `verify=False` deshabilitaba la comprobación de certificados SSL. Esta regla obliga a comprobar siempre los certificados SSL de los métodos de la biblioteca de peticiones. En la versión 23.7.4.0, los certificados se validan por defecto, que es el comportamiento deseado.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-07-24 CVE Reserved
- 2023-08-04 CVE Published
- 2024-08-10 EPSS Updated
- 2024-10-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-311: Missing Encryption of Sensitive Data
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/mindsdb/mindsdb/releases/tag/v23.7.4.0 | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/mindsdb/mindsdb/commit/083afcf6567cf51aa7d89ea892fd97689919053b | 2023-08-10 |
URL | Date | SRC |
---|---|---|
https://github.com/mindsdb/mindsdb/security/advisories/GHSA-8hx6-qv6f-xgcw | 2023-08-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mindsdb Search vendor "Mindsdb" | Mindsdb Search vendor "Mindsdb" for product "Mindsdb" | < 23.7.4.0 Search vendor "Mindsdb" for product "Mindsdb" and version " < 23.7.4.0" | - |
Affected
|