Critical ArangoDB Flaws Allow Authentication Bypass and Remote Code Execution as Root
Two critical flaws in ArangoDB can let an outsider bypass login controls, read or alter database data, and then gain root-level code execution on the underlying host. The issues affect installations through version 3.12.10.1, creating serious risk for internet-facing databases and container deployments. The attack does not rely on stolen passwords, a user click, or […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
