Lucene search

K
cvelistApacheCVELIST:CVE-2022-43766
HistoryOct 26, 2022 - 12:00 a.m.

CVE-2022-43766 Apache IoTDB prior to 0.13.3 allows DoS

2022-10-2600:00:00
apache
www.cve.org
cve-2022-43766
apache iotdb
dos
untrusted regexp queries
java 8
upgrade

0.002 Low

EPSS

Percentile

55.2%

Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. Users should upgrade to 0.13.3 which addresses this issue or use a later version of Java to avoid it.

CNA Affected

[
  {
    "vendor": "Apache Software Foundation",
    "product": "Apache IoTDB",
    "versions": [
      {
        "version": "unspecified",
        "lessThanOrEqual": "0.13.2",
        "status": "affected",
        "versionType": "custom"
      },
      {
        "version": "0.12.2",
        "status": "affected",
        "lessThan": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

0.002 Low

EPSS

Percentile

55.2%

Related for CVELIST:CVE-2022-43766