Apache IoTDB
cpe:2.3:a:apache:iotdb:*:*:*:*:*:*:*
- >= 1.0.0, < 1.3.4
A remote code execution vulnerability has been identified in Apache IoTDB versions 1.0.0 prior to 1.3.4. This issue arises from the ability of an attacker with privileges to create user-defined functions (UDFs) to register malicious functions from untrusted URIs.
Exploitation of this vulnerability allows for remote code execution on the server where Apache IoTDB is running.
Users are advised to upgrade to Apache IoTDB version 1.3.4 or later, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.