Vulnerability Description
Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Iotdb | 0.13.0 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2022/09/05/2Mailing ListThird Party Advisory
- https://lists.apache.org/thread/kcpqgstvgf8sxy9ktxm1836nlwc8xy3jMailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2022/09/05/2Mailing ListThird Party Advisory
- https://lists.apache.org/thread/kcpqgstvgf8sxy9ktxm1836nlwc8xy3jMailing ListVendor Advisory
FAQ
What is CVE-2022-38370?
CVE-2022-38370 is a vulnerability with a CVSS score of 7.5 (HIGH). Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses t...
How severe is CVE-2022-38370?
CVE-2022-38370 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-38370?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Iotdb.