Description
The JSONP endpoint in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict callback values, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted HTTP request.
Remediation
References
https://www.kb.cert.org/vuls/id/845332
https://github.com/orientechnologies/orientdb/issues/4824
Related Vulnerabilities
CVE-2020-35149 Vulnerability in npm package rxdb
CVE-2021-44585 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base
CVE-2018-1000412 Vulnerability in maven package org.jenkins-ci.plugins:jira
CVE-2023-31417 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2022-41249 Vulnerability in maven package com.meowlomo.jenkins:scm-httpclient