Unrated severityNVD Advisory· Published Feb 9, 2022· Updated Sep 16, 2024
ArangoDB - Blind SSRF when Downloading Foxx Service from URL
CVE-2021-25939
Description
In ArangoDB, versions v3.7.0 through v3.9.0-alpha.1 have a feature which allows downloading a Foxx service from a publicly available URL. This feature does not enforce proper filtering of requests performed internally, which can be abused by a highly-privileged attacker to perform blind SSRF and send internal requests to localhost.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/arangodb/arangodb/commit/d7b35a6884c6b2802d34d79fb2a79fb2c9ec2175mitrex_refsource_MISC
- github.com/arangodb/arangodb/commit/d9b7f019d2435f107b19a59190bf9cc27d5f34ddmitrex_refsource_MISC
- www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25939mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.