|
Message-ID: <23f62888-1023-1f89-651a-0f858e91c770@apache.org> Date: Mon, 30 Jan 2023 15:41:45 +0000 From: Jialin Qiao <qiaojialin@...che.org> To: oss-security@...ts.openwall.com Subject: CVE-2023-24829: Apache IoTDB: apache/iotdb-web-workbench: forge the JWTToken to access workbench Description: Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB iotdb-web-workbench.This issue affects users' access to the system without authorization. This CVE is fixed in iotdb-web-workbench tag v0.13.3. References: https://iotdb.apache.org/ https://iotdb.apache.org https://www.cve.org/CVERecord?id=CVE-2023-24829
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.