iotdbGHSA-g6hg-4v3c-6jq7
Apache IoTDB subject to ReDOS with Java 8
High7.5CVE-2022-43766 · Published Oct 26, 2022 · updated Jun 9, 2026
Apache IoTDB versions 0.12.2 through 0.12.6, and 0.13.0 through 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. This issue is patched in 0.13.3. Users should upgrade or use a later version of Java to avoid it.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-iotdb PyPI | >= 0.12.2, < 0.13.3 | 0.13.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-400
- Also known as
- CVE-2022-43766, PYSEC-2022-42972
More iotdb advisories
All iotdb| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jan 152024 | Remote Code Execution vulnerability in Apache IoTDB via UDF | High9.8 | 1.3.0 |
| Apr 172023 | Apache IoTDB Grafana Connector vulnerable to Improper Authentication | Critical9.8 | 0.13.5 |
| Apr 172023 | iotdb: improper authorization | Unrated | No fix yet |
| Jan 312023 | iotdb: improper authorization | Unrated | 0.13.3 |
| Jan 302023 | iotdb: improper authentication | Unrated | 0.13.3 |
| Sep 62022 | Apache IoTDB Session Fixation vulnerability | Medium8.8 | 0.13.1 |