[MAVEN:GHSA-F23H-52HJ-99P6] Apache IoTDB: Unsafe deserialize map in Sync Tool

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4.

Users are recommended to upgrade to version 1.2.2, which fixes the issue.

Package Affected Version
pkg:maven/org.apache.iotdb/iotdb-parent >= 0.13.0, < 1.2.2
Package Fixed Version
pkg:maven/org.apache.iotdb/iotdb-parent = 1.2.2
ID
MAVEN:GHSA-F23H-52HJ-99P6
Severity
high
URL
https://github.com/advisories/GHSA-f23h-52hj-99p6
Published
2023-12-21T12:30:29
(9 months ago)
Modified
2023-12-21T18:10:57
(9 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.iotdb/iotdb-parent org.apache.iotdb iotdb-parent >= 0.13.0 < 1.2.2
Fixed pkg:maven/org.apache.iotdb/iotdb-parent org.apache.iotdb iotdb-parent = 1.2.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...