CVE-2023-24830: Apache IoTDB Workbench: apache/iotdb-web-workbench: create a user without authorization
Withdrawn Advisory This advisory has been withdrawn because the affected component, org.apache.iotdb.admin:iotdb-web-workbench, is not in a supported ecosystem. This link is maintained to preserve external references.
Original Description Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before 0.13.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24830?
The severity of CVE-2023-24830 is high, with a severity value of 7.5.
What is the affected software for CVE-2023-24830?
The affected software for CVE-2023-24830 is Apache Software Foundation Apache IoTDB.
How can I fix CVE-2023-24830?
To fix CVE-2023-24830, update the affected component, iotdb-web-workbench, to a supported version (0.13.3 or higher).
What is the Common Weakness Enumeration (CWE) for CVE-2023-24830?
The Common Weakness Enumeration (CWE) for CVE-2023-24830 is CWE-287.
Where can I find more information about CVE-2023-24830?
You can find more information about CVE-2023-24830 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-24830), [Apache mailing list](https://lists.apache.org/thread/l4fon37687jz5ohgsnz2ko9fv400915t), [GitHub Advisory](https://github.com/advisories/GHSA-pp4w-9x82-6r47).