GHSA-c86f-9grv-pmqf
Dashboard / Vulnerabilities / GHSA-c86f-9grv-pmqf
Summary: Apache IoTDB grafana-connector contains an interface without authorization
Details: Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of a database. Users should upgrade to version 0.13.1, which addresses this issue.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-38370, https://github.com/apache/iotdb, https://github.com/pypa/advisory-database/tree/main/vulns/apache-iotdb/PYSEC-2022-43070.yaml, https://lists.apache.org/thread/kcpqgstvgf8sxy9ktxm1836nlwc8xy3j, http://www.openwall.com/lists/oss-security/2022/09/05/2
Affected packages
Package
Name: org.apache.iotdb:iotdb-grafana-connector
Purl: pkg:maven/org.apache.iotdb/iotdb-grafana-connector
Affected ranges
Type: ECOSYSTEM
Events:
