7.5

CVE-2025-26864

Apache IoTDB: Exposure of Sensitive Information in IoTDB OpenID Authentication

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB.

This issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2.

Users are recommended to upgrade to version 1.3.4 and 2.0.2, which fix the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Iotdb Version >= 0.10.0 < 1.3.4
Apache ≫ Iotdb Version 2.0.1 Update beta
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.72% 0.509
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

https://lists.apache.org/thread/2kcjnlypppk8qjh17dpz0jvkcpn6l162
Vendor Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2025/05/14/4
Mailing List