Описание
Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue.
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListVendor Advisory
- Mailing ListThird Party Advisory
- Mailing ListVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:apache:iotdb:0.13.0:*:*:*:*:*:*:*
EPSS
Процентиль: 76%
0.00918
Низкий
7.5 High
CVSS3
Дефекты
CWE-862
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
Apache IoTDB grafana-connector contains an interface without authorization
EPSS
Процентиль: 76%
0.00918
Низкий
7.5 High
CVSS3
Дефекты
CWE-862