Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ArcadeDB before 26.7.2 Cluster Token Disclosure via GET /api/v1/server
Vulnerability Description
ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-ArcadeDB-Cluster-Token and X-ArcadeDB-Forwarded-User headers to impersonate root and execute administrative actions including user creation, database operations, and server shutdown.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
信息暴露
Vulnerability Title
Arcade Data ArcadeDB 信息泄露漏洞
Vulnerability Description
ArcadeData arcadedb是ArcadeData的消息队列中间件。 Arcade Data ArcadeDB 26.7.2之前版本存在信息泄露漏洞,该漏洞源于未正确隐藏GET /api/v1/server端点中的集群令牌,导致已认证用户能够以明文检索arcadedb.ha.clusterToken值,攻击者可利用泄露的令牌配合X-ArcadeDB-Cluster-Token和X-ArcadeDB-Forwarded-User标头冒充root并执行创建用户、数据库操作及服务器关闭等管理操作。
CVSS Information
N/A
Vulnerability Type
N/A