CVE-2023-30771
published 2023-04-17CVE-2023-30771: Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.45%
70.2th percentile
Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotdb-web-workbench is an optional component of IoTDB, providing a web console of the database.
This problem is fixed from version 0.13.4 of iotdb-web-workbench onwards.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | iotdb_web_workbench | — | — |
| apache_software_foundation | apache_iotdb_workbench | >= 0.13.3 < 0.13.4 | 0.13.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-787r-6wxc-cg5f: Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB
ghsa_unreviewed·2023-04-17
CVE-2023-30771 [CRITICAL] CWE-863 GHSA-787r-6wxc-cg5f: Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB
Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotdb-web-workbench is an optional component of IoTDB, providing a web console of the database.
This problem is fixed from version 0.13.4 of iotdb-web-workbench onwards.
OSV
CVE-2023-30771: Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB
osv·2023-04-17
CVE-2023-30771 CVE-2023-30771: Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB
Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotdb-web-workbench is an optional component of IoTDB, providing a web console of the database.
This problem is fixed from version 0.13.4 of iotdb-web-workbench onwards.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-04-17
Published