Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackers to execute arbitrary OS commands via a crafted request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OrientDB 安全漏洞
Vulnerability Description
OrientDB是英国Orient公司一套开源的NoSQL数据库管理系统。该系统支持ACID事务、快速索引和SQL查询等功能。 OrientDB 2.22及之前的版本中存在安全漏洞,该漏洞源于程序没有强制执行权限请求。远程攻击者可通过发送特制的请求利用该漏洞执行任意的操作系统命令。
CVSS Information
N/A
Vulnerability Type
N/A