Insecure SSL Certificate Validation in MindsDB's AI Virtual Database

Insecure SSL Certificate Validation in MindsDB's AI Virtual Database

CVE-2023-38699 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource. Prior to version 23.7.4.0, a call to requests with `verify=False` disables SSL certificate checks. This rule enforces always verifying SSL certificates for methods in the Requests library. In version 23.7.4.0, certificates are validated by default, which is the desired behavior.

Learn more about our Web Application Penetration Testing UK.