CVE-2023-24831: Apache IoTDB grafana-connector Login Bypass Vulnerability
Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB. This issue affects Apache IoTDB Grafana Connector from 0.13.0 through 0.13.3.
Attackers could log in without authorization. This is fixed in 0.13.4.
Other sources
Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 through 0.13.3.
Attackers could login without authorization. This is fixed in 0.13.4.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-24831.
What is the severity of CVE-2023-24831?
The severity of CVE-2023-24831 is critical, with a CVSS score of 9.8.
What is the affected software?
The affected software is Apache IoTDB Grafana Connector version 0.13.0 through 0.13.3.
How can attackers exploit this vulnerability?
Attackers can exploit this vulnerability by logging in without authorization.
How can I fix CVE-2023-24831?
You can fix CVE-2023-24831 by updating to version 0.13.4 of Apache IoTDB Grafana Connector.