affected: - package: ecosystem: PyPI name: apache-iotdb purl: pkg:pypi/apache-iotdb ranges: - events: - introduced: '0' type: ECOSYSTEM versions: - 0.10.0 - 0.10.1 - 0.11.0 - 0.11.1 - 0.11.2 - 0.11.3 - 0.11.4 - 0.12.0 - 0.12.1 - 0.12.2 - 0.12.3 - 0.12.4 - 0.12.5 - 0.12.6 - 0.13.0 - 0.13.0.post1 - 0.13.1 - 0.13.2 - 0.13.3 - 0.13.5 - 0.13.5.1 - 0.14.0rc1 - 0.9.0 - 0.9.2 - 0.9.3 - 1.0.0 - 1.0.1 - 1.1.0 - 1.1.2 - 1.2.0 - 1.2.1 - 1.3.0 - 1.3.2 - 1.3.2.post0 - 1.3.3 aliases: - CVE-2022-38370 details: Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue. id: PYSEC-2022-43070 modified: '2024-11-21T14:22:40.90699Z' published: '2022-09-05T10:15:00Z' references: - type: ARTICLE url: https://lists.apache.org/thread/kcpqgstvgf8sxy9ktxm1836nlwc8xy3j - type: ADVISORY url: https://lists.apache.org/thread/kcpqgstvgf8sxy9ktxm1836nlwc8xy3j - type: ARTICLE url: http://www.openwall.com/lists/oss-security/2022/09/05/2 - type: WEB url: http://www.openwall.com/lists/oss-security/2022/09/05/2 severity: - score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N type: CVSS_V3 withdrawn: '2024-11-22T04:37:03Z'