CVE-2025-26795

Source
https://cve.org/CVERecord?id=CVE-2025-26795
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-26795.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-26795
Aliases
Published
2025-05-14T10:43:05.586Z
Modified
2026-07-15T01:48:57.344740059Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Apache IoTDB JDBC driver: Exposure of Sensitive Information in IoTDB JDBC driver
Details

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver.

This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2.

Users are recommended to upgrade to version 2.0.2 and 1.3.4, which fix the issue.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/26xxx/CVE-2025-26795.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "0.10.0"
                },
                {
                    "last_affected": "1.3.3"
                },
                {
                    "introduced": "2.0.1-beta"
                },
                {
                    "fixed": "2.0.2"
                }
            ]
        },
        {
            "source": "DESCRIPTION",
            "extracted_events": [
                {
                    "introduced": "0.10.0"
                },
                {
                    "fixed": "1.3.3"
                },
                {
                    "introduced": "2.0.1-beta"
                },
                {
                    "fixed": "2.0.2"
                }
            ]
        }
    ],
    "cna_assigner": "apache",
    "cwe_ids": [
        "CWE-200",
        "CWE-532"
    ]
}
References

Affected packages

Git / github.com/apache/iotdb

Affected ranges

Type
GIT
Repo
https://github.com/apache/iotdb
Events
Database specific
{
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0.10.0"
        },
        {
            "fixed": "1.3.4"
        },
        {
            "introduced": "2.0.1"
        },
        {
            "fixed": "2.0.2"
        }
    ],
    "cpe": "cpe:2.3:a:apache:iotdb:*:*:*:*:*:*:*:*"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-26795.json"