ArangoDB maintains a graph and document database product whose vulnerability profile centers on web-application and session-management weaknesses, including cross-site scripting, insufficient session expiration, and server-side request forgery. Current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Arangodb over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25940HIGH In ArangoDB, versions v3.7.6 through v3.8.3 are vulnerable to Insufficient Session Expiration. When a user’s password is changed by the administrator, the session isn’t invalidated | Nov 16, 2021 | 8.0 | 24 | NO | NO |
CVE-2021-25938MEDIUM In ArangoDB, versions v2.2.6.2 through v3.7.10 are vulnerable to Cross-Site Scripting (XSS), since there is no validation of the .zip file name and filtering of potential abusive c | May 24, 2021 | 6.1 | 19 | NO | NO |
In ArangoDB, versions v3.7.0 through v3.9.0-alpha.1 have a feature which allows downloading a Foxx service from a publicly available URL. This feature does not enforce proper filte | Feb 9, 2022 | 2.7 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Arangodb.
Media articles that mention a CVE ID that affects a product developed by Arangodb — matched by CVE ID, not by vendor name.