← Back

Arangodb

arangodb

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Arangodb
arangodb

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Arangodb
1Arangodb
Nov 21, 2024
Feb 9, 2022
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
In ArangoDB, versions v3.7.0 through v3.9.0-alpha.1 have a feature which allows downloading a Foxx service from a publicly available URL. This feature does not enforce proper filtering of requests performed internally, w...Show more
In ArangoDB, versions v3.7.0 through v3.9.0-alpha.1 have a feature which allows downloading a Foxx service from a publicly available URL. This feature does not enforce proper filtering of requests performed internally, which can be abused by a highly-privileged attacker to perform blind SSRF and send internal requests to localhost.Show less
1Arangodb
1Arangodb
Nov 21, 2024
Nov 16, 2021
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
In ArangoDB, versions v3.7.6 through v3.8.3 are vulnerable to Insufficient Session Expiration. When a user’s password is changed by the administrator, the session isn’t invalidated, allowing a malicious user to still be...Show more
In ArangoDB, versions v3.7.6 through v3.8.3 are vulnerable to Insufficient Session Expiration. When a user’s password is changed by the administrator, the session isn’t invalidated, allowing a malicious user to still be logged in and perform arbitrary actions within the system.Show less
1Arangodb
1Arangodb
Nov 21, 2024
May 24, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive characters which zip files can be named t...Show more
In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive characters which zip files can be named to. There is no X-Frame-Options Header set, which makes it more susceptible for leveraging self XSS by attackers.Show less