{"id":"CVE-2024-24759","aliases":["GHSA-4jcv-vp96-94xr","PYSEC-2024-74"],"url":"https://o3.security/vulnerability/CVE-2024-24759","summary":"MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding","details":"MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service. Version 23.12.4.2 contains a patch.","published":"2024-09-05T16:30:38.659Z","modified":"2026-07-15T01:49:16.755872956Z","cvss":{"score":9.3,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"mindsdb","fixedVersion":"23.12.4.2"}],"fix":{"url":"https://github.com/mindsdb/mindsdb/commit/5f7496481bd3db1d06a2d2e62c0dce960a1fe12b","label":"mindsdb/mindsdb@5f74964"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/24xxx/CVE-2024-24759.json"},{"type":"ADVISORY","url":"https://github.com/mindsdb/mindsdb/security/advisories/GHSA-4jcv-vp96-94xr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-24759"},{"type":"FIX","url":"https://github.com/mindsdb/mindsdb/commit/5f7496481bd3db1d06a2d2e62c0dce960a1fe12b"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:16.755872956Z"}}