Impact
The vulnerability arises from an improper limitation of a pathname to a restricted directory. When an attacker exploits the pipe file transfer receiver API, they can write arbitrary files to any location where the IoTDB process has write permission. Although the flaw does not guarantee that the written files will be executed, it enables arbitrary file creation and placement, potentially compromising data integrity IoTDB versions 1.0.0 through 2.0.9. All deployments running open source time‑series database maintained by the Apache Software Foundation.
Affected Systems
The affected systems include Apache Software Foundation's Apache IoTDB, specifically versions 1.0.0 up to (but not including) 2.0.10. All deployments of the open source time‑series database that run these versions are vulnerable.
Risk and Exploitability
With a CVSS score of 9.1 the vulnerability is classified as critical, but the EPSS score of less than 1% indicates a low current exploitation probability. The flaw is not listed in the CISA KEV catalog. The attack vector is remote, accessed via the pipe file transfer receiver API, and can be triggered over the network by an adversary who can reach the service. Authentication requirements are not specified in the advisory, so that assumption is inferred.
OpenCVE Enrichment