arcadedb-engine is vulnerable to Path Traversal
77
High Risk
LoadCSVStep opens a file:// URL or a bare filesystem path with FileInputStream and returns each line as a query row. OpenCypher does not require an administrative permission on that path, and the file URL setting defaults to enabled with an empty import directory, so a user who can run a read query on the server can read any file the server process can read. The fix requires the updateSecurity permission before that local file branch runs.
You are affected if you are using a version that falls within the vulnerable range and a non-admin user can run OpenCypher on the server.
arcadedb-engine is vulnerable to Path Traversal in versions 26.2.1 - 26.7.3.
Upgrade the com.arcadedb:arcadedb-engine library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.