CVE-2022-38369

HIGH

Apache IoTDB 0.13.0 - Session Fixation

Title source: llm
STIX 2.1

Description

Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.

References (2)

Core 2
Core References
Mailing List, Vendor Advisory x_refsource_misc
https://lists.apache.org/thread/7nk03ywvx3t3yjbcxzt7zy4nyc89y9b0
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2022/09/05/1

Scores

CVSS v3 8.8
EPSS 0.0102
EPSS Percentile 58.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-384
Status published
Products (3)
apache/iotdb 0.13.0
org.apache.iotdb/iotdb-server 0 - 0.13.1Maven
pypi/apache-iotdb 0 - 0.13.1PyPI
Published Sep 05, 2022
Tracked Since Feb 18, 2026