24.12.4.0
6 years ago
1 days ago
Known vulnerabilities in the MindsDB package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
MindsDB is a MindsDB server, provides server capabilities to mindsdb native python library Affected versions of this package are vulnerable to Cross-site Scripting (XSS) whenever another user enumerates unsanitized items within the UI. An attacker can execute arbitrary JavaScript code by injecting malicious scripts into the input fields. How to fix Cross-site Scripting (XSS)? There is no fixed version for | [0,) |
MindsDB is a MindsDB server, provides server capabilities to mindsdb native python library Affected versions of this package are vulnerable to Deserialization of Untrusted Data within the Note:
This can only occur if the BYOM engine is changed in the config from the default How to fix Deserialization of Untrusted Data? There is no fixed version for | [23.10.2.0,) |
MindsDB is a MindsDB server, provides server capabilities to mindsdb native python library Affected versions of this package are vulnerable to Deserialization of Untrusted Data within the Note:
This can only occur if the BYOM engine is changed in the config from the default How to fix Deserialization of Untrusted Data? There is no fixed version for | [23.10.2.0,) |
MindsDB is a MindsDB server, provides server capabilities to mindsdb native python library Affected versions of this package are vulnerable to Deserialization of Untrusted Data within the Note: This can only occur if the BYOM engine is changed in the config from the default ‘venv’ to ‘inhouse’. How to fix Deserialization of Untrusted Data? There is no fixed version for | [23.10.3.0,) |
MindsDB is a MindsDB server, provides server capabilities to mindsdb native python library Affected versions of this package are vulnerable to Deserialization of Untrusted Data through the deserialization process within the How to fix Deserialization of Untrusted Data? There is no fixed version for | [23.3.2.0,) |
MindsDB is a MindsDB server, provides server capabilities to mindsdb native python library Affected versions of this package are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to an unsafe extraction which is performed using the How to fix Arbitrary File Write via Archive Extraction (Zip Slip)? There is no fixed version for | [0,) |