CyberRota Analysis
AI-GeneratedApache IoTDB versions 1.3.5 to 1.3.8 and 2.0.5 to 2.0.10 are vulnerable to an authorization bypass that allows unauthorized authenticated users to access sensitive last-value data through the /rest/v2/fastLastQuery endpoint. This flaw poses a significant risk to data confidentiality and integrity, making it critical for organizations using affected versions to prioritize upgrading to version 2.0.10 to mitigate potential data exposure.
Original NVD Description
Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users. This issue affects Apache IoTDB: from 1.3.5 before 1.3.8, from 2.0.5 before 2.0.10. Users are recommended to upgrade to version 2.0.10, which fixes the issue.