漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
漏洞
OrientDB 3.0.17 Cross-Site Request Forgery
漏洞信息
OrientDB 3.0.17 GA Community Edition contains cross-site request forgery vulnerabilities that allow attackers to perform unauthorized actions by crafting malicious requests to endpoints like /database/, /command/, and /document/. Attackers can create or delete databases, modify schema classes, manage users, and create functions by sending authenticated requests without token validation, combined with reflected and stored cross-site scripting vulnerabilities in the web interface.
漏洞信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
漏洞
跨站请求伪造(CSRF)
漏洞
OrientDB 跨站请求伪造漏洞
漏洞信息
OrientDB是OrientDB开源的一个多模型数据库。 OrientDB 3.0.17版本存在跨站请求伪造漏洞,该漏洞源于端点缺少令牌验证,可能导致跨站请求伪造攻击。
漏洞信息
N/A
漏洞
N/A