CVE-2026-24014
- EPSS 0.58%
- Veröffentlicht 06.07.2026 08:34:26
- Zuletzt bearbeitet 07.07.2026 17:49:04
Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an attacker may...
CVE-2025-64152
- EPSS 0.38%
- Veröffentlicht 26.06.2026 12:16:28
- Zuletzt bearbeitet 29.09.2026 19:10:00
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.6, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.6 and 2...
CVE-2025-55017
- EPSS 0.38%
- Veröffentlicht 26.06.2026 12:15:53
- Zuletzt bearbeitet 29.09.2026 20:10:00
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 2.0.0 before 2.0.6, from 1.0.0 before 1.3.6. Users are recommended to upgrade to version 1.3.6 and 2...
CVE-2026-24713
- EPSS 0.66%
- Veröffentlicht 09.03.2026 08:59:59
- Zuletzt bearbeitet 10.03.2026 18:57:14
Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.7 or 2.0.7, which fixes the issue.
CVE-2026-24015
- EPSS 0.58%
- Veröffentlicht 09.03.2026 08:57:45
- Zuletzt bearbeitet 10.03.2026 18:56:56
A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.7 or 2.0.7, which fixes the issue.
CVE-2025-48459
- EPSS 0.46%
- Veröffentlicht 24.09.2025 08:15:32
- Zuletzt bearbeitet 26.09.2026 00:10:00
Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to upgrade to version 2.0.5, which fixes the issue.
CVE-2025-48392
- EPSS 0.56%
- Veröffentlicht 24.09.2025 08:15:31
- Zuletzt bearbeitet 26.09.2026 00:10:00
A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0.4. Users are recommended to upgrade to version 2.0.5, which fixes the issue.
CVE-2025-26864
- EPSS 0.72%
- Veröffentlicht 14.05.2025 10:44:12
- Zuletzt bearbeitet 01.07.2025 19:23:28
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB. This issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2....
CVE-2025-26795
- EPSS 0.72%
- Veröffentlicht 14.05.2025 10:43:05
- Zuletzt bearbeitet 11.07.2025 16:16:19
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver. This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. Users ar...
CVE-2024-24780
- EPSS 1.35%
- Veröffentlicht 14.05.2025 10:42:20
- Zuletzt bearbeitet 01.07.2025 19:21:39
Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI. This issue affects Apache IoTDB: from 1.0.0 before 1.3.4. Users are reco...