We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-30771

Apache IoTDB Workbench: apache/iotdb-web-workbench: forge the JWTToken to access workbench



Description

Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component on 0.13.3. iotdb-web-workbench is an optional component of IoTDB, providing a web console of the database. This problem is fixed from version 0.13.4 of iotdb-web-workbench onwards.

Reserved 2023-04-16 | Published 2023-04-17 | Updated 2025-02-13 | Assigner apache

Problem types

CWE-863 Incorrect Authorization

Product status

Default status
unaffected

0.13.3 before 0.13.4
affected

References

lists.apache.org/thread/08nc3dr6lshfppx0pzmz5vbggdnzpojb vendor-advisory

www.openwall.com/lists/oss-security/2023/04/18/7

cve.org (CVE-2023-30771)

nvd.nist.gov (CVE-2023-30771)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2023-30771

Support options

Helpdesk Chat, Email, Knowledgebase