iotdbGHSA-rxgg-273w-rfw7
Remote Code Execution vulnerability in Apache IoTDB via UDF
High9.8CVE-2023-46226 · Published Jan 15, 2024 · updated Jun 20, 2025
Remote Code Execution vulnerability in Apache IoTDB. This issue affects Apache IoTDB from 1.0.0 through 1.2.2. Users are recommended to upgrade to version 1.3.0, which fixes the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-iotdb PyPI | >= 1.0.0, < 1.3.0 | 1.3.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-94
- Also known as
- CVE-2023-46226, PYSEC-2024-11
More iotdb advisories
All iotdb| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 142025 | Apache IoTDB Vulnerable to Remote Code Execution | Critical9.8 | 1.3.4 |
| Apr 172023 | Apache IoTDB Grafana Connector vulnerable to Improper Authentication | Critical9.8 | 0.13.5 |
| Apr 172023 | iotdb: improper authorization | Unrated | No fix yet |
| Jan 312023 | iotdb: improper authorization | Unrated | 0.13.3 |
| Jan 302023 | iotdb: improper authentication | Unrated | 0.13.3 |
| Oct 262022 | Apache IoTDB subject to ReDOS with Java 8 | High7.5 | 0.13.3 |