Product
Evergreen versions up to 3.17-beta1 contain a SQL injection vulnerability in the OpenSRF service, allowing remote unauthenticated attackers to execute arbitrary database queries.