Skip to content
iotdbGHSA-rxgg-273w-rfw7

Remote Code Execution vulnerability in Apache IoTDB via UDF

High9.8CVE-2023-46226 · Published Jan 15, 2024 · updated Jun 20, 2025

Remote Code Execution vulnerability in Apache IoTDB. This issue affects Apache IoTDB from 1.0.0 through 1.2.2. Users are recommended to upgrade to version 1.3.0, which fixes the issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-iotdb
PyPI
>= 1.0.0, < 1.3.01.3.0
Details and references

More iotdb advisories

All iotdb
Advisory
Apache IoTDB Vulnerable to Remote Code Execution
Critical9.8May 14, 2025
Apache IoTDB Grafana Connector vulnerable to Improper Authentication
Critical9.8Apr 17, 2023
iotdb: improper authorization
UnratedApr 17, 2023
iotdb: improper authorization
UnratedJan 31, 2023
iotdb: improper authentication
UnratedJan 30, 2023
Apache IoTDB subject to ReDOS with Java 8
High7.5Oct 26, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.