CVE-2020-1952: Critical severity apache iotdb vulnerability
An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, clients could execute code remotely.
Affected Software
Event History
Frequently Asked Questions
What is Apache IoTDB vulnerability CVE-2020-1952?
Apache IoTDB 0.8.0 to 0.8.2 and 0.9.0 to 0.9.1 are affected by a critical vulnerability that exposes the JMX port 31999 without certification, allowing remote code execution.
How severe is CVE-2020-1952?
CVE-2020-1952 has a severity rating of 9.8 (critical).
Which versions of Apache IoTDB are affected by CVE-2020-1952?
Apache IoTDB versions 0.8.0 to 0.8.2 and 0.9.0 to 0.9.1 are affected by CVE-2020-1952.
How can the CVE-2020-1952 vulnerability be exploited?
The CVE-2020-1952 vulnerability in Apache IoTDB can be exploited by remotely executing code when the JMX port 31999 is exposed without certification.
Is there a fix available for CVE-2020-1952?
To fix CVE-2020-1952, users should update to a version of Apache IoTDB that is not affected by the vulnerability.