2.0.11
4 years ago
9 days ago
Known vulnerabilities in the org.apache.iotdb:node-commons package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
Affected versions of this package are vulnerable to Directory Traversal in the How to fix Directory Traversal? Upgrade | [1.0.0,2.0.10) |
Affected versions of this package are vulnerable to Directory Traversal in the DataNode internal RPC interface for creating Trigger instances, which builds a file path from the uploaded Trigger JAR name without sufficient validation. An attacker can write arbitrary files with the permissions of the IoTDB process by placing path traversal sequences in the JAR name, causing files to be written outside the intended Trigger installation directory. Exploitation requires the internal DataNode RPC port to be reachable from an untrusted network, so deployments that keep that port on a trusted internal network are not exposed. How to fix Directory Traversal? Upgrade | [1.3.3,2.0.8) |