Critical ArangoDB Flaws Allow Authentication Bypass and Remote Code Execution as Root

Two critical flaws in ArangoDB can let an outsider bypass login controls, read or alter database data, and then gain root-level code execution on the underlying host. The issues affect installations through version 3.12.10.1, creating serious risk for internet-facing databases and container deployments. The attack does not rely on stolen passwords, a user click, or […]

This article has been indexed from Cyber Security News

Read the original article: