CVE-2023-46226
Remote Code Execution vulnerability in Apache IoTDB via UDF
9.8
CRITICAL
CVSS 3.1
EPSS 1.9%
Description
Remote Code Execution vulnerability in Apache IoTDB. This issue affects Apache IoTDB from 1.0.0 through 1.2.2. Users are recommended to upgrade to version 1.3.0, which fixes the issue.
How to fix CVE-2023-46226
To remediate CVE-2023-46226, upgrade the affected package to a fixed version below.
- Maven/org.apache.iotdb:iotdb-core—upgrade to 1.3.0 or later
- —upgrade to 1.3.0 or later
- —upgrade to 1.3.0 or later
Is CVE-2023-46226 being exploited?
Low — EPSS is 1.9%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- >= 1.0.0, < 1.3.0
- >= 1.0.0, < 1.3.0
- >= 1.0.0, < 1.3.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U |
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |