CVE-2023-24830
published 2023-01-30CVE-2023-24830: Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before 0.13.3.
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.33%
67.9th percentile
Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before 0.13.3.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | iotdb | >= 0.13.0 < 0.13.3 | 0.13.3 |
| apache_software_foundation | apache_iotdb_workbench | >= 0.13.0 < 0.13.3 | 0.13.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Withdrawn Advisory: Apache IoTDB contains Improper Authentication
ghsa·2023-01-30
CVE-2023-24830 [HIGH] CWE-287 Withdrawn Advisory: Apache IoTDB contains Improper Authentication
Withdrawn Advisory: Apache IoTDB contains Improper Authentication
## Withdrawn Advisory
This advisory has been withdrawn because the affected component, `org.apache.iotdb.admin:iotdb-web-workbench`, is not in a [supported ecosystem](https://github.com/github/advisory-database/blob/main/README.md#supported-ecosystems). This link is maintained to preserve external references.
## Original Description
Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before 0.13.3.
OSV
CVE-2023-24830: Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB
osv·2023-01-30
CVE-2023-24830 CVE-2023-24830: Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB
Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 before 0.13.3.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-30
Published