CyberRota Analysis
AI-GeneratedThe Apache IoTDB DataNode is vulnerable due to inadequate validation of the uploaded Trigger JAR name, allowing attackers to exploit path traversal sequences to write files outside the designated installation directory. This critical vulnerability could lead to arbitrary file writes with the permissions of the IoTDB process, posing significant risks to system integrity and confidentiality. Organizations using affected versions of Apache IoTDB (1.3.3 to 2.0.7) should prioritize upgrading to version 2.0.8 to mitigate this risk.
Original NVD Description
Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to write files outside the intended Trigger installation directory. This could allow arbitrary file write with the permissions of the IoTDB process. This issue affects Apache IoTDB: from 1.3.3 before 2.0.8. Users are recommended to upgrade to version 2.0.8, which fixes the issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)