Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver.
This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2.
Users are recommended to upgrade to version 2.0.2 and 1.3.4, which fix the issue.
| Score | Percentile |
|---|---|
| 0.49% | 65.54% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 7.5 | 3.1 | — |
|
| 6.9 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-gp98-hfvm-2r4x ↗ |
| CVE | CVE-2025-26795 ↗ |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| maven | org.apache.iotdb:iotdb-jdbc | >= 0.10.0, < 1.3.4 | 1.3.4 | — |
| maven | org.apache.iotdb:iotdb-jdbc | >= 2.0.1-beta, < 2.0.2 | 2.0.2 | — |