First published: Mon Apr 17 2023(Updated: )
Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB. This issue affects Apache IoTDB Grafana Connector from 0.13.0 through 0.13.3. Attackers could log in without authorization. This is fixed in 0.13.4.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache IoTDB | >=0.13.0<=0.13.3 | |
pip/apache-iotdb | >=0.13.0<0.13.5 | 0.13.5 |
maven/org.apache.iotdb:iotdb-grafana-connector | >=0.13.0<0.13.4 | 0.13.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-24831.
The severity of CVE-2023-24831 is critical, with a CVSS score of 9.8.
The affected software is Apache IoTDB Grafana Connector version 0.13.0 through 0.13.3.
Attackers can exploit this vulnerability by logging in without authorization.
You can fix CVE-2023-24831 by updating to version 0.13.4 of Apache IoTDB Grafana Connector.