Apache

Iotdb

15 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.4%
  • Veröffentlicht 26.10.2022 16:15:11
  • Zuletzt bearbeitet 07.05.2025 14:15:37

Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. Users should upgrade to 0.13.3 which addresses this issue or use a later version of...

  • EPSS 1.87%
  • Veröffentlicht 05.09.2022 10:15:09
  • Zuletzt bearbeitet 21.11.2024 07:16:20

Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.

  • EPSS 0.92%
  • Veröffentlicht 05.09.2022 10:15:09
  • Zuletzt bearbeitet 21.11.2024 07:16:20

Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue.

  • EPSS 0.01%
  • Veröffentlicht 03.12.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:18:20

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.

  • EPSS 1.65%
  • Veröffentlicht 27.04.2020 17:15:13
  • Zuletzt bearbeitet 21.11.2024 05:11:43

An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, clients could execute code remotely.