PT-2026-57108 · Apache · Apache Iotdb
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache IoTDB versions 2.0.8 through 2.0.9
Description
Improper Privilege Management and Improper Access Control allow authenticated users to escalate their privileges to obtain full tree-path access. This is achieved by renaming the user account to
internal auditor.Recommendations
Upgrade to version 2.0.10.
Fix
Improper Privilege Management
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Iotdb