PT-2026-55879 · Apache · Apache Iotdb
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Apache IoTDB versions 1.3.3 through 2.0.7
Description
An authentication bypass issue exists due to insufficient validation of the
sessionId parameter within certain Thrift RPC query handlers. An attacker can forge the sessionId to bypass the openSession authentication process, allowing unauthorized access to and reading of time-series data.Recommendations
Upgrade to version 2.0.8.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Iotdb