CVE-2023-38502

Source
https://cve.org/CVERecord?id=CVE-2023-38502
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-38502.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-38502
Aliases
  • GHSA-w23f-r2fm-27hf
Published
2023-07-25T21:14:22.087Z
Modified
2026-04-10T05:52:42.800490Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
TDengine Database Denial-of-Service
Details

TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to version 3.0.7.1, TDengine DataBase crashes on UDF nested query. This issue affects TDengine Databases which let users connect and run arbitrary queries. Version 3.0.7.1 has a patch for this issue.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-20"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/38xxx/CVE-2023-38502.json"
}
References

Affected packages

Git / github.com/taosdata/tdengine

Affected ranges

Type
GIT
Repo
https://github.com/taosdata/tdengine
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other
autoaddcol_07161108
release/ver-2.*
release/ver-2.1.2.0
ver-1.*
ver-1.6.2.0
ver-1.6.2.1
ver-1.6.2.2
ver-1.6.3.0
ver-1.6.3.1
ver-1.6.5.0-beta
ver-1.6.5.1-beta
ver-1.6.5.2-beta
ver-1.6.5.3-beta
ver-1.6.5.3.aidong-beta
ver-2.*
ver-2.0.0.2
ver-2.0.0.3
ver-2.0.0.4
ver-2.0.2.0
ver-2.0.2.2-beta
ver-2.0.8.2
ver-2.1.0
ver-3.*
ver-3.0.3.0
ver-3.0.4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-38502.json"