Description
The JSONP endpoint in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict callback values, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted HTTP request.
Remediation
References
https://github.com/orientechnologies/orientdb/issues/4824
https://www.kb.cert.org/vuls/id/845332
Related Vulnerabilities
CVE-2019-10277 Vulnerability in maven package hudson.plugins:starteam
CVE-2023-30094 Vulnerability in npm package total4
CVE-2012-5885 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2020-2242 Vulnerability in maven package org.jenkins-ci.plugins:database
CVE-2021-39168 Vulnerability in npm package @openzeppelin/contracts-upgradeable