First published: Thu Dec 21 2023(Updated: )
Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4. Users are recommended to upgrade to version 1.2.2, which fixes the issue.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.iotdb:iotdb-parent | >=0.13.0<1.2.2 | 1.2.2 |
>=0.13.0<=0.13.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-51656 has been classified with a high severity due to its potential impact on data integrity and application security.
To fix CVE-2023-51656, users must upgrade Apache IoTDB to version 1.2.2 or later.
Apache IoTDB versions from 0.13.0 to 0.13.4 are affected by CVE-2023-51656.
CVE-2023-51656 is a Deserialization of Untrusted Data vulnerability.
Users running Apache IoTDB versions 0.13.0 through 0.13.4 are affected by CVE-2023-51656.