Vendor
Mooncake Store versions through 0.3.13.post1 contain a missing authentication vulnerability in the coro_rpc port, allowing unauthenticated attackers to perform unauthorized deletion operations.