Iotdb
Apache · 21 CVEs
Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC
Jul 6, 2026
Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query
Jul 6, 2026
Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write
Jul 6, 2026
Apache IoTDB: JEXL Expression Injection Vulnerability
Mar 9, 2026
Apache IoTDB: Insecure Default Configuration Vulnerability
Mar 9, 2026
Apache IoTDB: DoS Vulnerability
Sep 24, 2025
Apache IoTDB: Deserialization of untrusted Data
Sep 24, 2025
Apache IoTDB: Exposure of Sensitive Information in IoTDB OpenID Authentication
May 14, 2025
Apache IoTDB JDBC driver: Exposure of Sensitive Information in IoTDB JDBC driver
May 14, 2025
Apache IoTDB: Remote Code Execution with untrusted URI of User-defined function
May 14, 2025
Apache IoTDB: Remote Code Execution (RCE) risk via the UDF
Jan 15, 2024
Apache IoTDB: Unsafe deserialize map in Sync Tool
Dec 21, 2023
Apache IoTDB Workbench: apache/iotdb-web-workbench: forge the JWTToken to access workbench
Apr 17, 2023
Apache IoTDB grafana-connector Login Bypass Vulnerability
Apr 17, 2023
Apache IoTDB Workbench: apache/iotdb-web-workbench: forge the JWTToken to access workbench
Jan 31, 2023
Apache IoTDB Workbench: apache/iotdb-web-workbench: create a user without authorization
Jan 30, 2023
Apache IoTDB prior to 0.13.3 allows DoS
Oct 26, 2022
No authorization of DatabaseConnectController in grafana-connector.
Sep 5, 2022
Login check vulnerability by session Id
Sep 5, 2022
jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE)
Dec 3, 2020
An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed…
Apr 27, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-24013 | Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC | CRITICAL | 0.64% | Jul 6, 2026 |
| CVE-2026-24012 | Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query | HIGH | 0.74% | Jul 6, 2026 |
| CVE-2026-24014 | Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write | CRITICAL | 0.69% | Jul 6, 2026 |
| CVE-2026-24713 | Apache IoTDB: JEXL Expression Injection Vulnerability | CRITICAL | 0.66% | Mar 9, 2026 |
| CVE-2026-24015 | Apache IoTDB: Insecure Default Configuration Vulnerability | CRITICAL | 0.58% | Mar 9, 2026 |
| CVE-2025-48392 | Apache IoTDB: DoS Vulnerability | MEDIUM | 0.60% | Sep 24, 2025 |
| CVE-2025-48459 | Apache IoTDB: Deserialization of untrusted Data | CRITICAL | 0.49% | Sep 24, 2025 |
| CVE-2025-26864 | Apache IoTDB: Exposure of Sensitive Information in IoTDB OpenID Authentication | MEDIUM | 0.72% | May 14, 2025 |
| CVE-2025-26795 | Apache IoTDB JDBC driver: Exposure of Sensitive Information in IoTDB JDBC driver | MEDIUM | 0.72% | May 14, 2025 |
| CVE-2024-24780 | Apache IoTDB: Remote Code Execution with untrusted URI of User-defined function | CRITICAL | 1.35% | May 14, 2025 |
| CVE-2023-46226 | Apache IoTDB: Remote Code Execution (RCE) risk via the UDF | HIGH | 1.92% | Jan 15, 2024 |
| CVE-2023-51656 | Apache IoTDB: Unsafe deserialize map in Sync Tool | CRITICAL | 1.03% | Dec 21, 2023 |
| CVE-2023-30771 | Apache IoTDB Workbench: apache/iotdb-web-workbench: forge the JWTToken to access workbench | CRITICAL | 1.45% | Apr 17, 2023 |
| CVE-2023-24831 | Apache IoTDB grafana-connector Login Bypass Vulnerability | CRITICAL | 1.22% | Apr 17, 2023 |
| CVE-2023-24829 | Apache IoTDB Workbench: apache/iotdb-web-workbench: forge the JWTToken to access workbench | HIGH | 1.24% | Jan 31, 2023 |
| CVE-2023-24830 | Apache IoTDB Workbench: apache/iotdb-web-workbench: create a user without authorization | HIGH | 1.33% | Jan 30, 2023 |
| CVE-2022-43766 | Apache IoTDB prior to 0.13.3 allows DoS | HIGH | 1.46% | Oct 26, 2022 |
| CVE-2022-38370 | No authorization of DatabaseConnectController in grafana-connector. | HIGH | 1.35% | Sep 5, 2022 |
| CVE-2022-38369 | Login check vulnerability by session Id | MEDIUM | 1.27% | Sep 5, 2022 |
| CVE-2020-25649 | jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) | HIGH | 17.26% | Dec 3, 2020 |
| CVE-2020-1952 | An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, clients cou… | HIGH | 2.68% | Apr 27, 2020 |
Showing 1 to 21 of 21 CVEs