Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-38369.json"