Описание
MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource. Prior to version 23.7.4.0, a call to requests with verify=False disables SSL certificate checks. This rule enforces always verifying SSL certificates for methods in the Requests library. In version 23.7.4.0, certificates are validated by default, which is the desired behavior.
Ссылки
- Patch
- Release Notes
- Vendor Advisory
- Patch
- Release Notes
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 23.7.4.0 (исключая)
cpe:2.3:a:mindsdb:mindsdb:*:*:*:*:*:*:*:*
EPSS
Процентиль: 27%
0.00093
Низкий
9.1 Critical
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-311
Связанные уязвимости
CVSS3: 9.1
github
больше 2 лет назад
MindsDB can be made to not verify SSL certificates
EPSS
Процентиль: 27%
0.00093
Низкий
9.1 Critical
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-311