VYPR
High severityNVD Advisory· Updated Aug 3, 2024

No authorization of DatabaseConnectController in grafana-connector.

CVE-2022-38370

Description

Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.iotdb:iotdb-grafana-connectorMaven
< 0.13.10.13.1

Affected products

1
  • Apache Software Foundation/Apache IoTDBv5
    Range: 0.13.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.