Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
ArcadeDB before 26.8.1 Authentication Bypass via Async Command
Vulnerability Description
ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted with awaitResponse:false, it executes on an async worker whose DatabaseContext has no bound user, causing the scripting authorization gate to become a no-op. A user with only read access to a single database can submit an asynchronous JavaScript (language=js) command via the /api/v1/command endpoint to run code with unrestricted host access (e.g., database.getSecurity().createUser) and create a server-wide administrator, escalating to full administrative control. Fixed in 26.8.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
特权管理不恰当
Vulnerability Title
Arcade Data ArcadeDB 权限许可和访问控制问题漏洞
Vulnerability Description
Arcade Data ArcadeDB是Arcade Data组织的一款高性能原生多模型数据库。 Arcade Data ArcadeDB 26.7.3及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于未能将已认证主体传播到异步命令工作线程,导致脚本授权门禁失效,具有单个数据库只读权限的用户可通过/api/v1/command端点提交异步JavaScript命令,以不受限制的主机访问权限运行代码,创建服务器级管理员,从而导致权限提升。
CVSS Information
N/A
Vulnerability Type
N/A