This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2.
Users are recommended to upgrade to version 2.0.2 and 1.3.4, which fix the issue.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14872 | Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver. This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. Users are recommended to upgrade to version 2.0.2 and 1.3.4, which fix the issue. |
Github GHSA |
GHSA-gp98-hfvm-2r4x | Apache IoTDB JDBC Driver Discloses Sensitive Information via Log Files |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache iotdb |
|
| CPEs | cpe:2.3:a:apache:iotdb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache iotdb |
Mon, 19 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 14 May 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 14 May 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver. This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. Users are recommended to upgrade to version 2.0.2 and 1.3.4, which fix the issue. | |
| Title | Apache IoTDB JDBC driver: Exposure of Sensitive Information in IoTDB JDBC driver | |
| Weaknesses | CWE-200 CWE-532 |
|
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-05-19T18:43:08.129Z
Reserved: 2025-02-14T10:32:51.543Z
Link: CVE-2025-26795
Updated: 2025-05-14T11:04:03.962Z
Status : Analyzed
Published: 2025-05-14T11:16:26.487
Modified: 2025-07-11T16:16:19.057
Link: CVE-2025-26795
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA