GHSA-xm6r-4466-mr74
CRITICALCVE-2017-11467OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackers to execute arbitrary OS commands via a crafted request.
- Affected
- < 2.2.23
- Fixed in
- 2.2.23
- Weakness
- CWE-269
- Published
- 2018-10-18
- Source
- github