CVE-2022-43766: Apache IoTDB prior to 0.13.3 allows DoS
Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. Users should upgrade to 0.13.3 which addresses this issue or use a later version of Java to avoid it.
Other sources
Apache IoTDB versions 0.12.2 through 0.12.6, and 0.13.0 through 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. This issue is patched in 0.13.3. Users should upgrade or use a later version of Java to avoid it.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.iotdb:tsfileto a version that resolves this vulnerability.Fixed in 0.13.3 - Upgrade
Upgrade
maven/org.apache.iotdb:iotdb-serverto a version that resolves this vulnerability.Fixed in 0.13.3 - Upgrade
Upgrade
pip/apache-iotdbto a version that resolves this vulnerability.Fixed in 0.13.3 - Upgrade
Upgrade
maven/org.apache.iotdb:flink-tsfile-connectorto a version that resolves this vulnerability.Fixed in 0.13.3 - Upgrade
Upgrade
Apache IoTDBto a version that resolves this vulnerability.Fixed in 0.13.3 - Compensating control
Use a later version of Java than the vulnerable Java 8 configuration when running Apache IoTDB (vulnerable occurs when accepting untrusted patterns for REGEXP queries with Java 8).
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43766?
The severity of CVE-2022-43766 is high with a CVSS score of 7.5.
What is the vulnerability ID for Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2?
The vulnerability ID for Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 is CVE-2022-43766.
How can I mitigate the Denial of Service vulnerability in Apache IoTDB?
To mitigate the Denial of Service vulnerability in Apache IoTDB, users should upgrade to version 0.13.3 or use a later version of Java.
What is the affected software for CVE-2022-43766?
The affected software for CVE-2022-43766 is Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2.
Where can I find more information about CVE-2022-43766?
More information about CVE-2022-43766 can be found at this reference: [link](https://lists.apache.org/thread/9pgpb82p5brooy41n8l5q0y9h33db2zn).