First published: Mon Sep 05 2022(Updated: )
Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache IoTDB | =0.13.0 | |
pip/apache-iotdb | <0.13.1 | 0.13.1 |
maven/org.apache.iotdb:iotdb-server | <0.13.1 | 0.13.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2022-38369.
The severity level of CVE-2022-38369 is high with a CVSSv3 score of 8.8.
The affected software version of CVE-2022-38369 is Apache IoTDB 0.13.0.
To fix CVE-2022-38369, users should upgrade to version 0.13.1 of Apache IoTDB.
Yes, you can find references for CVE-2022-38369 at the following links: [Reference 1](http://www.openwall.com/lists/oss-security/2022/09/05/1) and [Reference 2](https://lists.apache.org/thread/7nk03ywvx3t3yjbcxzt7zy4nyc89y9b0).