HIGH 7.5 Maven
Apache IoTDB grafana-connector contains an interface without authorization
GHSA-c86f-9grv-pmqf · CVE-2022-38370
Published · Modified
Description
Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of a database. Users should upgrade to version 0.13.1, which addresses this issue.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2022-38370
- PACKAGE https://github.com/apache/iotdb
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/apache-iotdb/PYSEC-2022-43070.yaml
- WEB https://lists.apache.org/thread/kcpqgstvgf8sxy9ktxm1836nlwc8xy3j
- WEB http://www.openwall.com/lists/oss-security/2022/09/05/2
Ready to move
Start Securing
Free, no credit card | First findings in minutes