GHSA-gp98-hfvm-2r4x

Suggest an improvement
Source
https://github.com/advisories/GHSA-gp98-hfvm-2r4x
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/05/GHSA-gp98-hfvm-2r4x/GHSA-gp98-hfvm-2r4x.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-gp98-hfvm-2r4x
Aliases
Published
2025-05-14T12:31:11Z
Modified
2025-07-11T23:33:23.961301Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N CVSS Calculator
Summary
Apache IoTDB JDBC Driver Discloses Sensitive Information via Log Files
Details

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver.

This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2.

Users are recommended to upgrade to version 2.0.2 and 1.3.4, which fix the issue.

Database specific
{
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-200",
        "CWE-532"
    ],
    "severity": "MODERATE",
    "nvd_published_at": "2025-05-14T11:16:26Z",
    "github_reviewed_at": "2025-05-15T17:18:33Z"
}
References

Affected packages

Maven / org.apache.iotdb:iotdb-jdbc

Package

Name
org.apache.iotdb:iotdb-jdbc
View open source insights on deps.dev
Purl
pkg:maven/org.apache.iotdb/iotdb-jdbc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.10.0
Fixed
1.3.4

Affected versions

0.*

0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.12.3
0.12.4
0.12.5
0.12.6
0.13.0
0.13.1
0.13.2
0.13.3
0.13.4
0.14.0-preview1
0.14.0-preview2
0.14.0-preview3

1.*

1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3

Maven / org.apache.iotdb:iotdb-jdbc

Package

Name
org.apache.iotdb:iotdb-jdbc
View open source insights on deps.dev
Purl
pkg:maven/org.apache.iotdb/iotdb-jdbc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.1-beta
Fixed
2.0.2

Affected versions

2.*

2.0.1-beta