CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-26795: Apache IoTDB JDBC driver: Exposure of Sensitive Information in IoTDB JDBC driver

Description

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver.

This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2.

Users are recommended to upgrade to version 2.0.2 and 1.3.4, which fix the issue.

Classification

CVE ID: CVE-2025-26795

Problem Types

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor CWE-532 Insertion of Sensitive Information into Log File

Affected Products

Vendor: Apache Software Foundation

Product: Apache IoTDB JDBC driver

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.83% (scored less or equal to compared to others)

EPSS Date: 2025-06-12 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-26795
https://lists.apache.org/thread/bj0ytxr5wg0c4jw8xm7rhfd8ogho0r91

Timeline