---
id: CVE-2022-38369
aliases:
  - PYSEC-2022-43069
  - GHSA-g6vm-3ch8-c6jq
title: >-
  Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should
  upgrade to version 0.13.1 which addresses this issue.
summary: >-
  Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should
  upgrade to version 0.13.1 which addresses this issue.
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
vendor: apache-iotdb
product: apache-iotdb
ecosystem: pip
affected:
  - apache-iotdb < 0.13.1
patched:
  - apache-iotdb 0.13.1
published: '2022-09-05'
updated: '2026-07-01'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2022-43069'
references:
  - url: 'https://lists.apache.org/thread/7nk03ywvx3t3yjbcxzt7zy4nyc89y9b0'
  - url: 'https://lists.apache.org/thread/7nk03ywvx3t3yjbcxzt7zy4nyc89y9b0'
  - url: 'http://www.openwall.com/lists/oss-security/2022/09/05/1'
  - url: 'http://www.openwall.com/lists/oss-security/2022/09/05/1'
  - url: 'https://github.com/advisories/GHSA-g6vm-3ch8-c6jq'
tags:
  - osv
  - pip
epss: 0.01273
epssPercentile: 0.68659
ingestedAt: '2026-07-08T18:25:55.332Z'
---

## Overview

Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.

## Affected packages

- `apache-iotdb < 0.13.1`

## Remediation

Upgrade to a patched release:

- `apache-iotdb 0.13.1`
