Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://lists.apache.org/thread/kcpqgstvgf8sxy9ktxm1836nlwc8xy3j | mailing list vendor advisory |
http://www.openwall.com/lists/oss-security/2022/09/05/2 | third party advisory mailing list |