ArangoDB - Blind SSRF when Downloading Foxx Service from URL
Vulnerability Description
In ArangoDB, versions v3.7.0 through v3.9.0-alpha.1 have a feature which allows downloading a Foxx service from a publicly available URL. This feature does not enforce proper filtering of requests performed internally, which can be abused by a highly-privileged attacker to perform blind SSRF and send internal requests to localhost.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-25939
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- WhiteSource Vulnerability Research Team (WVR)
References
Affected Vendor
arangodb
View all reports →