CVE-2022-38370: No authorization of DatabaseConnectController in grafana-connector.
Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of a database. Users should upgrade to version 0.13.1, which addresses this issue.
Other sources
Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-38370?
CVE-2022-38370 is a vulnerability in Apache IoTDB grafana-connector version 0.13.0 that exposes an interface without authorization, potentially exposing the internal structure of the database.
How severe is CVE-2022-38370?
CVE-2022-38370 has a severity rating of 7.5 (high).
How does CVE-2022-38370 impact Apache IoTDB grafana-connector version 0.13.0?
CVE-2022-38370 may allow unauthorized users to access the internal structure of the database.
What should I do if I'm using Apache IoTDB grafana-connector version 0.13.0?
Users should upgrade to version 0.13.1 of Apache IoTDB grafana-connector to fix the vulnerability CVE-2022-38370.
Where can I find more information about CVE-2022-38370?
You can find more information about CVE-2022-38370 at the following references: [Reference 1](http://www.openwall.com/lists/oss-security/2022/09/05/2), [Reference 2](https://lists.apache.org/thread/kcpqgstvgf8sxy9ktxm1836nlwc8xy3j).