HIGH 8.8 Maven
Apache IoTDB Session Fixation vulnerability
GHSA-g6vm-3ch8-c6jq · CVE-2022-38369 · PYSEC-2022-43069
Published · Modified
Description
Apache IoTDB version 0.13.0 is vulnerable to session id attack. Users should upgrade to version 0.13.1 which addresses this issue.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2022-38369
- PACKAGE https://github.com/apache/iotdb
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/apache-iotdb/PYSEC-2022-43069.yaml
- WEB https://lists.apache.org/thread/7nk03ywvx3t3yjbcxzt7zy4nyc89y9b0
- WEB http://www.openwall.com/lists/oss-security/2022/09/05/1
Ready to move
Start Securing
Free, no credit card | First findings in minutes