CVE-2022-38369

CWE-3845 documents4 sources
Severity
8.8HIGH
EPSS
1.9%
top 16.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 5
Latest updateSep 6

Description

Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

🔴Vulnerability Details

4
GHSA
Apache IoTDB Session Fixation vulnerability2022-09-06
OSV
Apache IoTDB Session Fixation vulnerability2022-09-06
CVEList
Login check vulnerability by session Id2022-09-05
OSV
CVE-2022-38369: Apache IoTDB version 02022-09-05
CVE-2022-38369 (HIGH CVSS 8.8) | Apache IoTDB version 0.13.0 is vuln | cvebase.io