CVE-2022-43766
published 2022-10-26CVE-2022-43766: Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.34%
68.1th percentile
Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. Users should upgrade to 0.13.3 which addresses this issue or use a later version of Java to avoid it.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | iotdb | 0.12.2 – 0.12.6 | — |
| apache | iotdb | 0.13.0 – 0.13.2 | — |
| apache_software_foundation | apache_iotdb | >= 0.12.2 < unspecified | unspecified |
| apache_software_foundation | apache_iotdb | unspecified – 0.13.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache IoTDB subject to ReDOS with Java 8
ghsa·2022-10-26
CVE-2022-43766 [HIGH] CWE-400 Apache IoTDB subject to ReDOS with Java 8
Apache IoTDB subject to ReDOS with Java 8
Apache IoTDB versions 0.12.2 through 0.12.6, and 0.13.0 through 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. This issue is patched in 0.13.3. Users should upgrade or use a later version of Java to avoid it.
OSV
Apache IoTDB subject to ReDOS with Java 8
osv·2022-10-26
CVE-2022-43766 [HIGH] Apache IoTDB subject to ReDOS with Java 8
Apache IoTDB subject to ReDOS with Java 8
Apache IoTDB versions 0.12.2 through 0.12.6, and 0.13.0 through 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. This issue is patched in 0.13.3. Users should upgrade or use a later version of Java to avoid it.
OSV
CVE-2022-43766: Apache IoTDB version 0
osv·2022-10-26
CVE-2022-43766 CVE-2022-43766: Apache IoTDB version 0
Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. Users should upgrade to 0.13.3 which addresses this issue or use a later version of Java to avoid it.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-26
Published