PT-2022-27026 · Apache · Apache Iotdb

·

CVE-2022-43766

·

Published

2022-10-26

·

Updated

2025-05-07

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache IoTDB versions 0.12.2 through 0.12.6 Apache IoTDB versions 0.13.0 through 0.13.2
Description The issue is a Denial of Service attack that occurs when Apache IoTDB accepts untrusted patterns for REGEXP queries with Java 8. Users can avoid this issue by upgrading to version 0.13.3 or using a later version of Java.
Recommendations For Apache IoTDB versions 0.12.2 through 0.12.6, upgrade to version 0.13.3 or use a later version of Java to avoid the Denial of Service attack. For Apache IoTDB versions 0.13.0 through 0.13.2, upgrade to version 0.13.3 or use a later version of Java to avoid the Denial of Service attack.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-43766
GHSA-G6HG-4V3C-6JQ7
PYSEC-2022-42972

Affected Products

Apache Iotdb