iotdbGHSA-g6vm-3ch8-c6jq
Apache IoTDB Session Fixation vulnerability
Medium8.8CVE-2022-38369 · Published Sep 6, 2022 · updated Nov 26, 2024
Apache IoTDB version 0.13.0 is vulnerable to session id attack. Users should upgrade to version 0.13.1 which addresses this issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-iotdb PyPI | < 0.13.1 | 0.13.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-384
- Also known as
- CVE-2022-38369, PYSEC-2022-43069
More iotdb advisories
All iotdb| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jan 152024 | Remote Code Execution vulnerability in Apache IoTDB via UDF | High9.8 | 1.3.0 |
| Apr 172023 | Apache IoTDB Grafana Connector vulnerable to Improper Authentication | Critical9.8 | 0.13.5 |
| Apr 172023 | iotdb: improper authorization | Unrated | No fix yet |
| Jan 312023 | iotdb: improper authorization | Unrated | 0.13.3 |
| Jan 302023 | iotdb: improper authentication | Unrated | 0.13.3 |
| Oct 262022 | Apache IoTDB subject to ReDOS with Java 8 | High7.5 | 0.13.3 |