S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Feb 17, 2025

CVE-2024-24759 Scanner

MindsDB -DNS Rebinding SSRF Protection Bypass CVE-2024-24759 Scanner

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-24759
9.1
CVSScritical
Exploitable remotely over the internet · no authentication required.

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service. Version 23.12.4.2 contains a patch.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
mindsdbby mindsdb
< 23.12.4.2
mindsdbby mindsdb
AFFECTED< 23.12.4.2SAFE ✓≥ 23.12.4.2
Updated Aug 22, 2026View on NVD →
Detail

MindsDB is an open-source machine learning platform that enables developers to integrate machine learning models into their databases. It automates machine learning workflows, offering an easy-to-use interface for database management systems. With its simplicity and powerful algorithms, MindsDB supports tasks like predictive analytics and forecasting. The product is widely used in various industries to speed up data-driven decision-making. It is often deployed in production environments where scalability and security are crucial. This software is used by businesses and individuals to incorporate AI-driven insights into their operations.

The SSRF vulnerability detected in MindsDB allows an attacker to bypass SSRF protection mechanisms. It is caused by improper URL validation during DNS resolution. Specifically, DNS rebinding attacks are not properly considered during the validation process, enabling an attacker to manipulate DNS responses. This vulnerability can be exploited by attackers to make requests to internal services that are typically protected by SSRF mechanisms. The issue is present in versions before 23.12.4.2, where a patch was introduced to fix the DNS rebinding attack vector. Exploiting this flaw can lead to critical impacts in terms of unauthorized access to internal systems.

The vulnerability resides in the URL validation mechanism used by MindsDB. When performing DNS resolution for URLs, the software fails to properly handle DNS rebinding attacks. This means that an attacker can craft a DNS response that points to an internal service, bypassing security measures meant to prevent such attacks. The vulnerable parameter is the URL handling logic, which does not account for DNS rebinding threats. The flaw affects all versions of MindsDB prior to 23.12.4.2. The vulnerability can be triggered when an attacker sends a specially crafted URL that results in the software contacting internal resources. The malicious URL contains a DNS record that can be manipulated for exploitation.

If successfully exploited, the SSRF vulnerability can allow an attacker to bypass the protection mechanisms meant to safeguard internal services. This could lead to unauthorized access to sensitive information or internal systems. Attackers could gain access to otherwise restricted endpoints, potentially executing malicious commands or extracting confidential data. The exploitation of this vulnerability could be used as a stepping stone for further attacks, including privilege escalation or data exfiltration. In the worst-case scenario, it may enable attackers to compromise the entire application environment, leading to significant business impacts.

REFERENCES

Solution Advice
  • Upgrade to MindsDB version 23.12.4.2 or later to mitigate the vulnerability.
  • Ensure proper validation of URLs and DNS responses to avoid DNS rebinding attacks.
  • Review server-side request handling to ensure internal services are properly protected against unauthorized access.
  • Consider implementing additional network segmentation to isolate internal resources.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.