
oss-sec mailing list archives
CVE-2024-36448: Apache IoTDB Workbench: SSRF Vulnerability (EOL)
From: Haonan Hou <haonan () apache org>
Date: Mon, 05 Aug 2024 09:45:42 +0000
Severity: low Affected versions: - Apache IoTDB Workbench 0.13.0 or later Description: ** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench. This issue affects Apache IoTDB Workbench: from 0.13.0. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Credit: L0ne1y (finder) References: https://iotdb.apache.org https://www.cve.org/CVERecord?id=CVE-2024-36448
Current thread:
- CVE-2024-36448: Apache IoTDB Workbench: SSRF Vulnerability (EOL) Haonan Hou (Aug 05)