Description
The JSONP endpoint in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict callback values, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted HTTP request.
Remediation
References
https://github.com/orientechnologies/orientdb/issues/4824
https://www.kb.cert.org/vuls/id/845332
Related Vulnerabilities
CVE-2013-4322 Vulnerability in maven package org.apache.tomcat:coyote
CVE-2023-29471 Vulnerability in maven package com.typesafe.akka:akka-stream-kafka_3
CVE-2023-37478 Vulnerability in npm package @pnpm/macos-arm64
CVE-2023-40337 Vulnerability in maven package org.jenkins-ci.plugins:cloudbees-folder
CVE-2016-0706 Vulnerability in maven package org.apache.tomcat:catalina