Lucene search

K
githubGitHub Advisory DatabaseGHSA-PP4W-9X82-6R47
HistoryJan 30, 2023 - 6:30 p.m.

Withdrawn Advisory: Apache IoTDB contains Improper Authentication

2023-01-3018:30:28
CWE-287
GitHub Advisory Database
github.com
15
apache iotdb
improper authentication
vulnerability

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.006 Low

EPSS

Percentile

79.0%

Withdrawn Advisory

This advisory has been withdrawn because the affected component, org.apache.iotdb.admin:iotdb-web-workbench, is not in a supported ecosystem. This link is maintained to preserve external references.

Original Description

Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before 0.13.3.

Affected configurations

Vulners
Node
org.apache.iotdb\iotdbMatchparent
CPENameOperatorVersion
org.apache.iotdb:iotdb-parentlt0.13.3

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

0.006 Low

EPSS

Percentile

79.0%

Related for GHSA-PP4W-9X82-6R47