CVE-2023-24829: Apache IoTDB Workbench: apache/iotdb-web-workbench: forge the JWTToken to access workbench
Published Jan 31, 2023
·Updated
Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component from 0.13.0 before 0.13.3. iotdb-web-workbench is an optional component of IoTDB, providing a web console of the database.
This problem is fixed from version 0.13.3 of iotdb-web-workbench onwards.
Affected Software
1 affected component
Apache IoTDB>=0.13.0<0.13.3
Event History
Jan 31, 2023
CVE Published
via MITRE·09:22 AM
Data Sourced
via MITRE·09:22 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-24829.
2
What is the severity of CVE-2023-24829?
The severity of CVE-2023-24829 is high (8.8).
3
Which component is affected by this vulnerability?
The iotdb-web-workbench component from Apache IoTDB is affected by this vulnerability.
4
What is the affected version range of iotdb-web-workbench?
The affected version range of iotdb-web-workbench is from 0.13.0 to 0.13.3 (inclusive).
5
How can I fix this vulnerability?
You can fix this vulnerability by updating the iotdb-web-workbench component to version 0.13.3 or later.