CVE-2022-43766

CVE-2022-43766: Apache IoTDB prior to 0.13.3 allows DoS

Vendor Apache Software Foundation
Product Apache IoTDB
Published October 26, 2022
Last update May 7, 2025

CVSS base score

What the vulnerability does

Description

Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. Users should upgrade to 0.13.3 which addresses this issue or use a later version of Java to avoid it.

Key dates

Disclosure timeline

October 26, 2022 CVE published
May 7, 2025 Record updated