Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ArcadeDB before 26.8.1 SSRF via IMPORT DATABASE validator bypass
Vulnerability Description
ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command where the security validator resolves and checks hostnames but the subsequent connection re-resolves the raw URL and follows redirects. Authenticated attackers can bypass the validator using DNS rebinding or HTTP redirects to access cloud metadata endpoints, internal services, or read arbitrary local files on default installations.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Arcade Data ArcadeDB 服务端请求伪造漏洞
Vulnerability Description
Arcade Data ArcadeDB是Arcade Data组织的一款高性能原生多模型数据库。 Arcade Data ArcadeDB 26.8.1之前版本存在服务端请求伪造漏洞,该漏洞源于IMPORT DATABASE命令中安全验证器解析并检查主机名后,后续连接重新解析原始URL并跟随重定向,可能导致经过身份验证的攻击者利用DNS重绑定或HTTP重定向绕过验证器,访问云元数据端点、内部服务或读取任意本地文件。
CVSS Information
N/A
Vulnerability Type
N/A