CVE Vulnerabilities

CVE-2020-1952

Improper Certificate Validation

Published: Apr 27, 2020 | Modified: May 04, 2020
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, clients could execute code remotely.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Iotdb Apache 0.8.0 (including) 0.8.2 (including)
Iotdb Apache 0.9.0 (including) 0.9.1 (including)

Potential Mitigations

References