CVE-2022-38369: Login check vulnerability by session Id
Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.
Other sources
Apache IoTDB version 0.13.0 is vulnerable to session id attack. Users should upgrade to version 0.13.1 which addresses this issue.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-38369.
What is the severity level of CVE-2022-38369?
The severity level of CVE-2022-38369 is high with a CVSSv3 score of 8.8.
What is the affected software version of CVE-2022-38369?
The affected software version of CVE-2022-38369 is Apache IoTDB 0.13.0.
How can I fix CVE-2022-38369?
To fix CVE-2022-38369, users should upgrade to version 0.13.1 of Apache IoTDB.
Are there any references for CVE-2022-38369?
Yes, you can find references for CVE-2022-38369 at the following links: [Reference 1](http://www.openwall.com/lists/oss-security/2022/09/05/1) and [Reference 2](https://lists.apache.org/thread/7nk03ywvx3t3yjbcxzt7zy4nyc89y9b0).