OSV 1.4.0 · github-reviewed · 修改于 2026-07-17 04:05
发布时间
2026-07-17 04:05
GitHub 审查时间
2026-07-17 04:05
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/07/GHSA-8w86-m9h8-hvqg/GHSA-8w86-m9h8-hvqg.json
The SQL IMPORT DATABASE statement did not require administrative privileges and passed its source URL to the importer without validation. Any authenticated user with SQL command access (not only root/administrators) could therefore:
169.254.169.254) and internal-only services, and ingest the responses as queryable records./etc/passwd, credential files) by importing file:// paths, exposing their contents as records.The server administration endpoint (/api/v1/server) was already restricted to the root user and was not affected; the exposure was through the database SQL command/query endpoints (/api/v1/command, /api/v1/query).
A related lower-severity hardening gap (CWE-776): the XML importer did not disable DTD processing, leaving entity-expansion (Billion Laughs) possible.
integration/src/main/java/com/arcadedb/integration/importer/SourceDiscovery.java (no host allow-list for http(s); no path validation for file://), reached from engine/.../query/sql/parser/ImportDatabaseStatement.java.
IMPORT DATABASE now requires the administrative updateSecurity permission (no-op in embedded mode).SourceDiscovery: HTTP(S) hosts resolving to loopback / link-local / private (site-local) / wildcard / multicast addresses are blocked by default (arcadedb.server.security.importBlockLocalNetworks, default true), and an optional local-path allow-list (arcadedb.server.security.importAllowedLocalPaths) restricts file:// reads.Fixed in commit referenced by pull request #4422.
Restrict SQL command/query access to trusted administrative users; do not grant query access to untrusted users on servers that can reach sensitive networks or hold sensitive local files. Upgrading is strongly recommended.
Reported by Bin Luo ([email protected]).