Apache IoTDB
cpe:2.3:a:apache:iotdb:*:*:*:*:*:*:*
- >= 1.0.0, < 2.0.5
A deserialization of untrusted data vulnerability exists in Apache IoTDB versions 1.0.0 prior to 2.0.5. This vulnerability could potentially be exploited due to improper handling of serialized data, leading to unintended consequences.
Exploitation of this vulnerability could allow for deserialization attacks, where an attacker manipulates serialized data to execute arbitrary code or cause other harmful effects on the application.
Users are advised to upgrade to Apache IoTDB version 2.0.5 or later, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.