Apache IoTDB prior to 0.13.3 allows DoS
CVE-2022-43766

7.5HIGH

Key Information:

Vendor
Apache
Vendor
CVE Published:
26 October 2022

Summary

Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. Users should upgrade to 0.13.3 which addresses this issue or use a later version of Java to avoid it.

Affected Version(s)

Apache IoTDB <= 0.13.2

Apache IoTDB 0.12.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by 4ra1n of Chaitin Tech
.