Beveiligingsadvies

CVE-2021-25939

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-02-09 12:15:14
Laatst bijgewerkt 2024-09-16 18:29:04
Toegewezen door Mend
CVSS-score 2.7
Status PUBLISHED

Beschrijving

In ArangoDB, versions v3.7.0 through v3.9.0-alpha.1 have a feature which allows downloading a Foxx service from a publicly available URL. This feature does not enforce proper filtering of requests performed internally, which can be abused by a highly-privileged attacker to perform blind SSRF and send internal requests to localhost.