Lucene search

K
cvelistApacheCVELIST:CVE-2023-30771
HistoryApr 17, 2023 - 7:26 a.m.

CVE-2023-30771 Apache IoTDB Workbench: apache/iotdb-web-workbench: forge the JWTToken to access workbench

2023-04-1707:26:12
CWE-863
apache
www.cve.org
incorrect authorization
apache iotdb
forge jwttoken
vulnerability
fixed version 0.13.4
iotdb.

9.6 High

AI Score

Confidence

High

0.082 Low

EPSS

Percentile

94.4%

Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotdb-web-workbench is an optional component of IoTDB, providing a web console of the database.

This problem is fixed from version 0.13.4 of iotdb-web-workbench onwards.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Apache IoTDB Workbench",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThan": "0.13.4",
        "status": "affected",
        "version": "0.13.3",
        "versionType": "custom"
      }
    ]
  }
]

9.6 High

AI Score

Confidence

High

0.082 Low

EPSS

Percentile

94.4%

Related for CVELIST:CVE-2023-30771