GHSA-f23h-52hj-99p6

Suggest an improvement
Source
https://github.com/advisories/GHSA-f23h-52hj-99p6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-f23h-52hj-99p6/GHSA-f23h-52hj-99p6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-f23h-52hj-99p6
Aliases
  • CVE-2023-51656
Published
2023-12-21T12:30:29Z
Modified
2024-11-29T05:42:16.346142Z
Summary
Apache IoTDB: Unsafe deserialize map in Sync Tool
Details

Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4.

Users are recommended to upgrade to version 1.2.2, which fixes the issue.

Database specific
{
    "nvd_published_at": "2023-12-21T12:15:08Z",
    "cwe_ids": [
        "CWE-502"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2023-12-21T18:10:56Z"
}
References

Affected packages

Maven / org.apache.iotdb:iotdb-parent

Package

Name
org.apache.iotdb:iotdb-parent
View open source insights on deps.dev
Purl
pkg:maven/org.apache.iotdb/iotdb-parent

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.13.0
Fixed
1.2.2

Affected versions

0.*

0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0-preview1
0.14.0-preview2
0.14.0-preview3

1.*

1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1