This issue affects Apache IoTDB: from 1.0.0 before 2.0.5.
Users are recommended to upgrade to version 2.0.5, which fixes the issue.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-30951 | Apache IoTDB: Deserialization of untrusted Data |
Github GHSA |
GHSA-776q-jw43-fhjx | Apache IoTDB: Deserialization of untrusted Data |
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 25 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:iotdb:*:*:*:*:*:*:*:* |
Thu, 25 Sep 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache iotdb |
|
| Vendors & Products |
Apache
Apache iotdb |
Wed, 24 Sep 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 24 Sep 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to upgrade to version 2.0.5, which fixes the issue. | |
| Title | Apache IoTDB: Deserialization of untrusted Data | |
| Weaknesses | CWE-502 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-11-04T21:11:05.598Z
Reserved: 2025-05-22T06:25:16.580Z
Link: CVE-2025-48459
Updated: 2025-11-04T21:11:05.598Z
Status : Modified
Published: 2025-09-24T08:15:32.810
Modified: 2025-11-04T22:16:17.327
Link: CVE-2025-48459
No data.
OpenCVE Enrichment
Updated: 2025-09-25T08:21:39Z
EUVD
Github GHSA