com.arcadedb:arcadedb-server vulnerabilities
CVEs whose affected-version data names the com.arcadedb:arcadedb-server package (maven). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
GHSA-48qw-824m-86prHigh· 7.7ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read
ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read
▾ Twilightarcadedb · com.arcadedb:arcadedb-servervia GHSA
GHSA-x8mg-6r4p-87pfHighArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
ArcadeDB has cross-database IDOR: /ts/*, /batch/*, Prometheus and Grafana handlers bypass authorization
▾ Twilightarcadedb · com.arcadedb:arcadedb-servervia GHSA