Iotdb

Apache · 21 CVEs

CVE-2026-24013
CRITICAL

Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC

Jul 6, 2026

CVE-2026-24012
HIGH

Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query

Jul 6, 2026

CVE-2026-24014
CRITICAL

Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write

Jul 6, 2026

CVE-2026-24713
CRITICAL

Apache IoTDB: JEXL Expression Injection Vulnerability

Mar 9, 2026

CVE-2026-24015
CRITICAL

Apache IoTDB: Insecure Default Configuration Vulnerability

Mar 9, 2026

CVE-2025-48392
MEDIUM

Apache IoTDB: DoS Vulnerability

Sep 24, 2025

CVE-2025-48459
CRITICAL

Apache IoTDB: Deserialization of untrusted Data

Sep 24, 2025

CVE-2025-26864
MEDIUM

Apache IoTDB: Exposure of Sensitive Information in IoTDB OpenID Authentication

May 14, 2025

CVE-2025-26795
MEDIUM

Apache IoTDB JDBC driver: Exposure of Sensitive Information in IoTDB JDBC driver

May 14, 2025

CVE-2024-24780
CRITICAL

Apache IoTDB: Remote Code Execution with untrusted URI of User-defined function

May 14, 2025

CVE-2023-46226
HIGH

Apache IoTDB: Remote Code Execution (RCE) risk via the UDF

Jan 15, 2024

CVE-2023-51656
CRITICAL

Apache IoTDB: Unsafe deserialize map in Sync Tool

Dec 21, 2023

CVE-2023-30771
CRITICAL

Apache IoTDB Workbench: apache/iotdb-web-workbench: forge the JWTToken to access workbench

Apr 17, 2023

CVE-2023-24831
CRITICAL

Apache IoTDB grafana-connector Login Bypass Vulnerability

Apr 17, 2023

CVE-2023-24829
HIGH

Apache IoTDB Workbench: apache/iotdb-web-workbench: forge the JWTToken to access workbench

Jan 31, 2023

CVE-2023-24830
HIGH

Apache IoTDB Workbench: apache/iotdb-web-workbench: create a user without authorization

Jan 30, 2023

CVE-2022-43766
HIGH

Apache IoTDB prior to 0.13.3 allows DoS

Oct 26, 2022

CVE-2022-38370
HIGH

No authorization of DatabaseConnectController in grafana-connector.

Sep 5, 2022

CVE-2022-38369
MEDIUM

Login check vulnerability by session Id

Sep 5, 2022

CVE-2020-25649
HIGH

jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE)

Dec 3, 2020

CVE-2020-1952
HIGH

An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed…

Apr 27, 2020

Showing 1 to 21 of 21 CVEs