CVE-2022-38369

HIGH

Apache IoTDB <0.13.0 - SSRF

Title source: llm
STIX 2.1

Description

Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.

Scores

CVSS v3 8.8
EPSS 0.0187
EPSS Percentile 83.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-384
Status published
Products (3)
apache/iotdb 0.13.0
org.apache.iotdb/iotdb-server 0 - 0.13.1Maven
pypi/apache-iotdb 0 - 0.13.1PyPI
Published Sep 05, 2022
Tracked Since Feb 18, 2026