High severityNVD Advisory· Updated Aug 3, 2024
No authorization of DatabaseConnectController in grafana-connector.
CVE-2022-38370
Description
Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.iotdb:iotdb-grafana-connectorMaven | < 0.13.1 | 0.13.1 |
Affected products
1- Apache Software Foundation/Apache IoTDBv5Range: 0.13.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/advisories/GHSA-c86f-9grv-pmqfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-38370ghsaADVISORY
- www.openwall.com/lists/oss-security/2022/09/05/2ghsamailing-listx_refsource_MLISTWEB
- github.com/pypa/advisory-database/tree/main/vulns/apache-iotdb/PYSEC-2022-43070.yamlghsaWEB
- lists.apache.org/thread/kcpqgstvgf8sxy9ktxm1836nlwc8xy3jghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.