Security advisory: Pre-authent... Note

Security advisory: Pre-authentication RCE in Ontotext GraphDB 11.4.3 Free edition (Ontotext / Graphwise)

Posted by disclosure via Fulldisclosure on Aug 170day Rubbish Research Team is publicly disclosing a vulnerability in Ontotext GraphDB 11.4.3 Free edition (Ontotext / Graphwise). The research is published and a proof-of-concept is available. Pre-authentication RCE (CVSS 9.8, pre-authentication) Ontotext GraphDB 11.4.3 Free edition defaults to security=false, which bypasses the entire Spring Security filter chain. As a result, /rest/repositories/ruleset/upload and /repositories/* are...