CVE-2023-24829
EPSS 0.58%
Description
Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component from 0.13.0 before 0.13.3. iotdb-web-workbench is an optional component of IoTDB, providing a web console of the database. This problem is fixed from version 0.13.3 of iotdb-web-workbench onwards.
How to fix CVE-2023-24829
To remediate CVE-2023-24829, upgrade the affected package to a fixed version below.
- PyPI/apache-iotdb—upgrade to 0.13.3 or later
Is CVE-2023-24829 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 0.13.0, < 0.13.3