CVE-2025-26864
published 2025-05-14CVE-2025-26864: Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.71%
49.4th percentile
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB.
This issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2.
Users are recommended to upgrade to version 1.3.4 and 2.0.2, which fix the issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | iotdb | — | — |
| apache | iotdb | >= 0.10.0 < 1.3.4 | 1.3.4 |
| apache_software_foundation | apache_iotdb | 0.10.0 – 1.3.3 | — |
| apache_software_foundation | apache_iotdb | >= 2.0.1-beta < 2.0.2 | 2.0.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-26864: Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of
osv·2025-05-14
CVE-2025-26864 CVE-2025-26864: Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB.
This issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2.
Users are recommended to upgrade to version 1.3.4 and 2.0.2, which fix the issue.
GHSA
Apache IoTDB Discloses Sensitive Information via Log Files
ghsa·2025-05-14
CVE-2025-26864 [MEDIUM] CWE-200 Apache IoTDB Discloses Sensitive Information via Log Files
Apache IoTDB Discloses Sensitive Information via Log Files
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB.
This issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2.
Users are recommended to upgrade to version 1.3.4 and 2.0.2, which fix the issue.
OSV
Apache IoTDB Discloses Sensitive Information via Log Files
osv·2025-05-14
CVE-2025-26864 [MEDIUM] Apache IoTDB Discloses Sensitive Information via Log Files
Apache IoTDB Discloses Sensitive Information via Log Files
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB.
This issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2.
Users are recommended to upgrade to version 1.3.4 and 2.0.2, which fix the issue.
No detection rules found.
No public exploits indexed.
2025-05-14
Published