GHSA-8hx6-qv6f-xgcw

    Dashboard / Vulnerabilities / GHSA-8hx6-qv6f-xgcw

    GHSA-8hx6-qv6f-xgcw

    Published: 1 Aug 2023Last Modified: 13 Feb 2025

    Summary: MindsDB can be made to not verify SSL certificates

    Details: ### Summary MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource. Prior to version 23.7.4.0, a call to requests with `verify=False` disables SSL certificate checks. This rule enforces always verifying SSL certificates for methods in the Requests library. In version 23.7.4.0, certificates are validated by default, which is the desired behavior Encryption in general is typically critical to the security of many applications. Using TLS can significantly increase security by guaranteeing the identity of the party you are communicating with. This is accomplished by one or both parties presenting trusted certificates during the connection initialization phase of TLS. It is important to note that modules such as httplib within the Python standard library did not verify certificate chains until it was fixed in 2.7.9 release. ### Details Severity: Critical

    Affected packages

    Package

    Name: mindsdb

    Purl: pkg:pypi/mindsdb

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -23.7.4.0

    Affected versions

    0.6.5
    0.6.6
    0.6.7
    0.6.8
    0.6.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-8hx6-qv6f-xgcw | CVE-DB