PT-2022-9685 · Arangodb · Arangodb

Published

2022-02-09

·

Updated

2022-02-11

·

CVE-2021-25939

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ArangoDB versions v3.7.0 through v3.9.0-alpha.1
Description The issue in ArangoDB allows a highly-privileged attacker to perform blind Server-Side Request Forgery (SSRF) and send internal requests to localhost. This is due to a feature that enables downloading a Foxx service from a publicly available URL without proper filtering of internal requests.
Recommendations For ArangoDB versions v3.7.0 through v3.9.0-alpha.1, consider disabling the feature that allows downloading Foxx services from publicly available URLs until a patch is available. Restrict access to internal requests to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25939

Affected Products

Arangodb