Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-01018
HistoryDec 25, 2023 - 12:00 a.m.

Apache IoTDB Deserialization Vulnerability

2023-12-2500:00:00
China National Vulnerability Database
www.cnvd.org.cn
9
apache
iotdb
deserialization
vulnerability
data management
time-series
exploitation
arbitrary code
attack
system

8 High

AI Score

Confidence

Low

0.037 Low

EPSS

Percentile

91.8%

Apache IoTDB is an integrated data management engine designed for time-series data from the Apache (USA) Foundation, which provides data collection, storage, and analysis services, among other things. A deserialization vulnerability exists in Apache IoTDB versions 0.13.0 through 0.13.4, which can be exploited by an attacker to execute arbitrary code on a system.

CPENameOperatorVersion
apache iotdb >=0.13.0,le0.13.4

8 High

AI Score

Confidence

Low

0.037 Low

EPSS

Percentile

91.8%