CVE-2025-26795
published 2025-05-14CVE-2025-26795: Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver. This…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.71%
49.4th percentile
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver.
This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2.
Users are recommended to upgrade to version 2.0.2 and 1.3.4, which fix the issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | iotdb | >= 0.10.0 < 1.3.4 | 1.3.4 |
| apache | iotdb | >= 2.0.1 < 2.0.2 | 2.0.2 |
| apache_software_foundation | apache_iotdb_jdbc_driver | 0.10.0 – 1.3.3 | — |
| apache_software_foundation | apache_iotdb_jdbc_driver | >= 2.0.1-beta < 2.0.2 | 2.0.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache IoTDB JDBC Driver Discloses Sensitive Information via Log Files
ghsa·2025-05-14
CVE-2025-26795 [MEDIUM] CWE-200 Apache IoTDB JDBC Driver Discloses Sensitive Information via Log Files
Apache IoTDB JDBC Driver Discloses Sensitive Information via Log Files
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver.
This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2.
Users are recommended to upgrade to version 2.0.2 and 1.3.4, which fix the issue.
OSV
Apache IoTDB JDBC Driver Discloses Sensitive Information via Log Files
osv·2025-05-14
CVE-2025-26795 [MEDIUM] Apache IoTDB JDBC Driver Discloses Sensitive Information via Log Files
Apache IoTDB JDBC Driver Discloses Sensitive Information via Log Files
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver.
This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2.
Users are recommended to upgrade to version 2.0.2 and 1.3.4, which fix the issue.
No detection rules found.
No public exploits indexed.
2025-05-14
Published