PYSEC-2022-42972

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/apache-iotdb/PYSEC-2022-42972.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2022-42972
Aliases
Published
2022-10-26T16:15:00Z
Modified
2023-11-08T04:10:46.722728Z
Summary
[none]
Details

Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. Users should upgrade to 0.13.3 which addresses this issue or use a later version of Java to avoid it.

References

Affected packages

PyPI / apache-iotdb

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.13.0
Fixed
0.14.0rc1
Introduced
0.12.2
Fixed
0.13.0

Affected versions

0.*

0.12.2
0.12.3
0.12.4
0.12.5
0.12.6