漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ArcadeDB before 26.8.1 Authentication Bypass via Async Command
Vulnerability Description
ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted with awaitResponse:false, it executes on an async worker whose DatabaseContext has no bound user, causing the scripting authorization gate to become a no-op. A user with only read access to a single database can submit an asynchronous JavaScript (language=js) command via the /api/v1/command endpoint to run code with unrestricted host access (e.g., database.getSecurity().createUser) and create a server-wide administrator, escalating to full administrative control. Fixed in 26.8.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
特权管理不恰当
Vulnerability Title
Arcade Data ArcadeDB 权限许可和访问控制问题漏洞
Vulnerability Description
Arcade Data ArcadeDB是Arcade Data组织的一款高性能原生多模型数据库。 Arcade Data ArcadeDB 26.7.3及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于未能将已认证主体传播到异步命令工作线程,导致脚本授权门禁失效,具有单个数据库只读权限的用户可通过/api/v1/command端点提交异步JavaScript命令,以不受限制的主机访问权限运行代码,创建服务器级管理员,从而导致权限提升。
CVSS Information
N/A
Vulnerability Type
N/A