QID 980963
QID 980963: Java (maven) Security Update for com.orientechnologies:orientdb-studio (GHSA-p8ww-vv84-c2rm)
The JSONP endpoint in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict callback values, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted HTTP request.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-p8ww-vv84-c2rm for updates pertaining to this vulnerability.
Vendor References
- GHSA-p8ww-vv84-c2rm -
github.com/advisories/GHSA-p8ww-vv84-c2rm
CVEs related to QID 980963
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-p8ww-vv84-c2rm | com.orientechnologies:orientdb-studio |
|