CVE-2022-43766

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-43766
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-43766.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-43766
Aliases
Published
2022-10-26T16:15:11Z
Modified
2025-07-01T23:56:34.514313Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. Users should upgrade to 0.13.3 which addresses this issue or use a later version of Java to avoid it.

References

Affected packages

Git / github.com/apache/iotdb

Affected ranges

Affected versions

v0.*

v0.12.2
v0.12.3
v0.12.4
v0.12.5
v0.12.6
v0.13.0
v0.13.1
v0.13.2