CVE-2021-25939

CVE-2021-25939

In ArangoDB, versions v3.7.0 through v3.9.0-alpha.1 have a feature which allows downloading a Foxx service from a publicly available URL. This feature does not enforce proper filtering of requests performed internally, which can be abused by a highly-privileged attacker to perform blind SSRF and send internal requests to localhost.

Source: CVE-2021-25939

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다