Skip to content
iotdbGHSA-g6vm-3ch8-c6jq

Apache IoTDB Session Fixation vulnerability

Medium8.8CVE-2022-38369 · Published Sep 6, 2022 · updated Nov 26, 2024

Apache IoTDB version 0.13.0 is vulnerable to session id attack. Users should upgrade to version 0.13.1 which addresses this issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-iotdb
PyPI
< 0.13.10.13.1
Details and references

More iotdb advisories

All iotdb
Advisory
Remote Code Execution vulnerability in Apache IoTDB via UDF
High9.8Jan 15, 2024
Apache IoTDB Grafana Connector vulnerable to Improper Authentication
Critical9.8Apr 17, 2023
iotdb: improper authorization
UnratedApr 17, 2023
iotdb: improper authorization
UnratedJan 31, 2023
iotdb: improper authentication
UnratedJan 30, 2023
Apache IoTDB subject to ReDOS with Java 8
High7.5Oct 26, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.