This issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2.
Users are recommended to upgrade to version 1.3.4 and 2.0.2, which fix the issue.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14874 | Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB. This issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. Users are recommended to upgrade to version 1.3.4 and 2.0.2, which fix the issue. |
Github GHSA |
GHSA-5fc3-pqf2-57cx | Apache IoTDB Discloses Sensitive Information via Log Files |
Tue, 01 Jul 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache iotdb |
|
| CPEs | cpe:2.3:a:apache:iotdb:*:*:*:*:*:*:*:* cpe:2.3:a:apache:iotdb:2.0.1:beta:*:*:*:*:*:* |
|
| Vendors & Products |
Apache
Apache iotdb |
Mon, 19 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 14 May 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 14 May 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB. This issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. Users are recommended to upgrade to version 1.3.4 and 2.0.2, which fix the issue. | |
| Title | Apache IoTDB: Exposure of Sensitive Information in IoTDB OpenID Authentication | |
| Weaknesses | CWE-200 CWE-532 |
|
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-05-19T18:41:38.927Z
Reserved: 2025-02-17T09:52:26.132Z
Link: CVE-2025-26864
Updated: 2025-05-14T11:04:06.072Z
Status : Analyzed
Published: 2025-05-14T11:16:28.437
Modified: 2025-07-01T19:23:28.797
Link: CVE-2025-26864
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA