An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, clients could execute code remotely.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: apache

Published: 2020-04-27T16:16:12

Updated: 2020-04-27T16:16:12

Reserved: 2019-12-02T00:00:00


Link: CVE-2020-1952

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-04-27T17:15:13.533

Modified: 2020-05-04T14:25:51.327


Link: CVE-2020-1952

JSON object: View

cve-icon Redhat Information

No data.

CWE