CRITICAL🇵🇱 Wersja polska

CVE-2023-46226

CVSS 9.8v3.1pub. 2024-01-15upd. 2025-06-20

Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users are recommended to upgrade to version 1.3.0, which fixes the issue.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-94 (code injection) allows an attacker to inject and execute arbitrary code on a vulnerable Apache IoTDB server. The attack can be conducted remotely over the network without requiring an account or any user interaction. The detailed exploitation mechanism was not disclosed in the vendor's description.

Impact

Successful exploitation of the vulnerability gives the attacker full control over the system — data breach is possible, modification of the time series database, and potentially further lateral movement in the infrastructure.

Mitigation & patch

Apache IoTDB should be updated to version 1.3.0 or newer as soon as possible, which eliminates the described vulnerability. The vendor explicitly recommends this version as a solution to the problem.

Who is affected

Apache IoTDB in versions 1.0.0 to 1.2.2 inclusive.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apache Iotdb

    APP
    Apache
    1.0.0 – 1.3.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-24013CRITICAL9.1PL ✓same product

Apache IoTDB — pominięcie uwierzytelnienia przez sfałszowany sessionId (Thrift RPC)

CVE-2026-24014CRITICAL9.8PL ✓same product

Apache IoTDB: path traversal umożliwiający zapis dowolnych plików

CVE-2026-24015CRITICAL9.8PL ✓same product

Krytyczna podatność w Apache IoTDB (CVE-2026-24015)

CVE-2026-24713CRITICAL9.8PL ✓same product

Nieprawidłowa walidacja danych wejściowych w Apache IoTDB — RCE/injection

CVE-2024-24780CRITICAL9.8PL ✓same product

Apache IoTDB: RCE przez rejestrację złośliwej funkcji UDF z niezaufanego URI