PT-2022-27026 · Apache · Apache Iotdb
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Apache IoTDB versions 0.12.2 through 0.12.6
Apache IoTDB versions 0.13.0 through 0.13.2
Description
The issue is a Denial of Service attack that occurs when Apache IoTDB accepts untrusted patterns for REGEXP queries with Java 8. Users can avoid this issue by upgrading to version 0.13.3 or using a later version of Java.
Recommendations
For Apache IoTDB versions 0.12.2 through 0.12.6, upgrade to version 0.13.3 or use a later version of Java to avoid the Denial of Service attack.
For Apache IoTDB versions 0.13.0 through 0.13.2, upgrade to version 0.13.3 or use a later version of Java to avoid the Denial of Service attack.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Iotdb