CVE-2023-51656: Apache IoTDB: Unsafe deserialize map in Sync Tool
Published Dec 21, 2023
·Updated
Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4.
Users are recommended to upgrade to version 1.2.2, which fixes the issue.
Affected Software
2 affected componentsFixes available
maven/org.apache.iotdb:iotdb-parent>=0.13.0<1.2.2
1.2.2
Apache IoTDB>=0.13.0<=0.13.4
Event History
Dec 21, 2023
CVE Published
via MITRE·11:47 AM
Data Sourced
via MITRE·11:47 AM
DescriptionWeakness
Advisory Published
via GitHub·12:30 PM
Data Sourced
via GitHub·12:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-51656?
CVE-2023-51656 has been classified with a high severity due to its potential impact on data integrity and application security.
2
How do I fix CVE-2023-51656?
To fix CVE-2023-51656, users must upgrade Apache IoTDB to version 1.2.2 or later.
3
What versions of Apache IoTDB are affected by CVE-2023-51656?
Apache IoTDB versions from 0.13.0 to 0.13.4 are affected by CVE-2023-51656.
4
What type of vulnerability is CVE-2023-51656?
CVE-2023-51656 is a Deserialization of Untrusted Data vulnerability.
5
Who is affected by CVE-2023-51656?
Users running Apache IoTDB versions 0.13.0 through 0.13.4 are affected by CVE-2023-51656.