CyberRota Analysis
AI-GeneratedTDengine, an open-source time-series database for IoT devices, has a vulnerability that allows a Data Reader admin_user to execute the "create udf" command, bypassing intended read-only permissions for standard users. This could lead to unauthorized modifications and potential data integrity issues. Organizations using versions prior to 3.4.1.15 should prioritize upgrading to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Reader admin_user on a TDengine Cloud DB instance could run create udf even though standard users should have read-only permissions for non-database objects and show dnodes and create user were denied. This issue is fixed in version 3.4.1.15.