Skip to content
iotdbGHSA-pvjv-386f-c8wh

Apache IoTDB Grafana Connector vulnerable to Improper Authentication

Critical9.8CVE-2023-24831 · Published Apr 17, 2023 · updated Sep 12, 2024

Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB. This issue affects Apache IoTDB Grafana Connector from 0.13.0 through 0.13.3. Attackers could log in without authorization. This is fixed in 0.13.4.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-iotdb
PyPI
>= 0.13.0, < 0.13.50.13.5
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-287
Also known as
CVE-2023-24831, PYSEC-2023-7

More iotdb advisories

All iotdb
Advisory
Remote Code Execution vulnerability in Apache IoTDB via UDF
High9.8Jan 15, 2024
iotdb: improper authorization
UnratedApr 17, 2023
iotdb: improper authorization
UnratedJan 31, 2023
iotdb: improper authentication
UnratedJan 30, 2023
Apache IoTDB subject to ReDOS with Java 8
High7.5Oct 26, 2022
Apache IoTDB Session Fixation vulnerability
Medium8.8Sep 6, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.