Impact
Apache IoTDB suffers from an authentication bypass due to insufficient session expiration. The server accepts stale cached credentials, allowing a replay attack where an attacker can reuse a previously captured credential to gain access. This flaw is classified as a capture‑replay vulnerability and falls under weaknesses in authentication management (CWE‑294) and insecure token handling (CWE‑613).
Affected Systems
All releases of Apache IoTDB from 1.0.0 up to, but not including, 2.0.10 are impacted. Users running these versions should confirm they are not using the vulnerable range and consider moving to the patched release.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, yet the EPSS score of less than 1% suggests that the likelihood of an exploit being seen in the wild is currently very low. The flaw is not listed in the CISA KEV catalog, but the vulnerable condition could be leveraged by a remote attacker who can reach the REST interface, making the attack vector remote over the network. The impact grants full access wherever the stolen credentials have authority, potentially compromising data confidentiality, integrity, and availability.
OpenCVE Enrichment