Apache IoTDB
cpe:2.3:a:apache:iotdb:*:*:*:*:*:*:*
- >= 0.10.0, <= 1.3.3
- >= 2.0.1-beta, < 2.0.2
A vulnerability has been identified in the OpenIdAuthorizer component of Apache IoTDB, versions 0.10.0 through 1.3.3 and 2.0.1-beta prior to 2.0.2. This issue involves the exposure of sensitive information to unauthorized actors and the insertion of sensitive data into log files.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information and its improper logging, potentially allowing for further exploitation or privacy violations.
Users are advised to upgrade to Apache IoTDB versions 1.3.4 or 2.0.2, both of which address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.