Description
Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.
Remediation
References
https://lists.apache.org/thread/7nk03ywvx3t3yjbcxzt7zy4nyc89y9b0
http://www.openwall.com/lists/oss-security/2022/09/05/1
Related Vulnerabilities
CVE-2022-22965 Vulnerability in maven package org.springframework.boot:spring-boot-starter-web
CVE-2023-34620 Vulnerability in maven package org.hjson:hjson
CVE-2020-2138 Vulnerability in maven package org.jenkins-ci.plugins:cobertura
CVE-2023-35147 Vulnerability in maven package org.jenkins-ci.plugins:aws-codecommit-trigger
CVE-2023-50779 Vulnerability in maven package com.cloudtp.jenkins:paaslane-estimate