Skip to main content

Vendor/product archive

apache / iotdb CVEs

Beta · best-effort

20 CVEs tagged to apache / iotdb9 Critical, 10 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-24014

Published Jul 6, 2026

Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the interna…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-24013

Published Jul 6, 2026

Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct req…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-24012

Published Jul 6, 2026

Uncontrolled Resource Consumption vulnerability in Apache IoTDB.  Some interface fails to impose reasonable limits on the time span and aggregation interval of the query. An atta…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-24713

Published Mar 9, 2026

Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrade to v…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-24015

Published Mar 9, 2026

A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.7 or 2.0.7, w…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-48459

Published Sep 24, 2025

Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0.5. Users are recommended to upgrade to version 2.0.5, whi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48392

Published Sep 24, 2025

A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0.4. Users are recommended to upgrade to version 2.0.5, whi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-26864

Published May 14, 2025

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB. This issue aff…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-26795

Published May 14, 2025

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver. This issue affects iotdb-j…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-24780

Published May 14, 2025

Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI. Th…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-46226

Published Jan 15, 2024

Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users are recommended to upgrade to version 1.3.0, which fixes the…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-51656

Published Dec 21, 2023

Deserialization of Untrusted Data vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 0.13.0 through 0.13.4. Users are recommended to upgrade to version 1.2.2, wh…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-24831

Published Apr 17, 2023

Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects Apache IoTDB Grafana Connector: from 0.13.0 through 0.13.3. Attackers could lo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-24829

Published Jan 31, 2023

Incorrect Authorization vulnerability in Apache Software Foundation Apache IoTDB.This issue affects the iotdb-web-workbench component from 0.13.0 before 0.13.3. iotdb-web-workbenc…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-24830

Published Jan 30, 2023

Improper Authentication vulnerability in Apache Software Foundation Apache IoTDB.This issue affects iotdb-web-workbench component: from 0.13.0 before 0.13.3.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43766

Published Oct 26, 2022

Apache IoTDB version 0.12.2 to 0.12.6, 0.13.0 to 0.13.2 are vulnerable to a Denial of Service attack when accepting untrusted patterns for REGEXP queries with Java 8. Users should…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-38370

Published Sep 5, 2022

Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.1…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-38369

Published Sep 5, 2022

Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1952

Published Apr 27, 2020

An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, clients could execute code remo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1