{"id":"GHSA-xm6r-4466-mr74","summary":"OrientDB vulnerable to Improper Privilage Management leading to arbitrary command injection","details":"OrientDB through 2.2.22 does not enforce privilege requirements during \"where\" or \"fetchplan\" or \"order by\" use, which allows remote attackers to execute arbitrary OS commands via a crafted request.","aliases":["CVE-2017-11467"],"modified":"2024-02-20T16:30:54.587986Z","published":"2018-10-18T17:40:56Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T22:03:45Z","nvd_published_at":null,"cwe_ids":["CWE-269"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-11467"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-xm6r-4466-mr74"},{"type":"PACKAGE","url":"https://github.com/orientechnologies/orientdb"},{"type":"WEB","url":"https://github.com/orientechnologies/orientdb/wiki/OrientDB-2.2-Release-Notes#2223---july-11-2017"},{"type":"WEB","url":"https://web.archive.org/web/20210403135751/http://www.heavensec.org/?p=1703"}],"affected":[{"package":{"name":"com.orientechnologies:orientdb-core","ecosystem":"Maven","purl":"pkg:maven/com.orientechnologies/orientdb-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.23"}]}],"versions":["1.0","1.0.1","1.0rc9","1.1.0","1.2.0","1.3.0","1.4.0","1.4.1","1.5.0","1.5.1","1.6","1.6.1","1.6.2","1.6.3","1.6.4","1.6.5","1.6.6","1.7","1.7-rc1","1.7-rc2","1.7.1","1.7.10","1.7.2","1.7.3","1.7.4","1.7.5","1.7.6","1.7.7","1.7.8","1.7.9","2.0","2.0-M1","2.0-M2","2.0-M3","2.0-rc1","2.0-rc2","2.0.1","2.0.10","2.0.11","2.0.12","2.0.13","2.0.14","2.0.15","2.0.16","2.0.17","2.0.18","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9","2.1-rc1","2.1-rc2","2.1-rc3","2.1-rc4","2.1-rc5","2.1-rc6","2.1.0","2.1.1","2.1.10","2.1.11","2.1.12","2.1.13","2.1.14","2.1.15","2.1.16","2.1.17","2.1.18","2.1.19","2.1.2","2.1.20","2.1.21","2.1.22","2.1.23","2.1.24","2.1.25","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.1.9","2.2.0","2.2.0-beta","2.2.0-beta2","2.2.0-rc1","2.2.1","2.2.10","2.2.11","2.2.12","2.2.13","2.2.14","2.2.15","2.2.16","2.2.17","2.2.18","2.2.19","2.2.2","2.2.20","2.2.21","2.2.22","2.2.3","2.2.4","2.2.5","2.2.6","2.2.7","2.2.8","2.2.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-xm6r-4466-mr74/GHSA-xm6r-4466-mr74.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}