Arbitrary Command Injection Affecting com.orientechnologies:orientdb-core package, versions [,2.2.23)


0.0
critical

Snyk CVSS

    Attack Complexity Low
    Confidentiality High
    Integrity High
    Availability High

    Threat Intelligence

    Exploit Maturity Mature
    EPSS 32.8% (97th percentile)
Expand this section
NVD
9.8 critical

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-JAVA-COMORIENTECHNOLOGIES-31559
  • published 5 Nov 2017
  • disclosed 29 Jun 2017
  • credit Unknown

How to fix?

Upgrade com.orientechnologies:orientdb-core to version 2.2.23 or higher.

Overview

com.orientechnologies:orientdb-core is an Open Source Multi-Model NoSQL DBMS with the support of Native Graphs, Documents Full-Text, Reactivity, Geo-Spatial and Object Oriented concepts.

Affected versions of the package are vulnerable to Arbitrary Command Injection, as does not enforce privilege requirements during where, fetchplan or order by use, which allows remote attackers to execute arbitrary OS commands via a crafted request.