Apache IoTDB: Unsafe deserialize map in Sync Tool
CVE-2023-51656

9.8CRITICAL

Key Information:

Vendor
Apache
Vendor
CVE Published:
21 December 2023

Summary

A deserialization of untrusted data vulnerability exists in Apache IoTDB versions 0.13.0 to 0.13.4, which could allow an attacker to manipulate the application's behavior by crafting malicious input data. It is crucial for users to upgrade to version 1.2.2 to remediate this issue, ensuring the security and integrity of data processing within IoTDB environments.

Affected Version(s)

Apache IoTDB 0.13.0 <= 0.13.4

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.