CVE-2025-26795 Details
Description
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver. This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. Users are recommended to upgrade to version 2.0.2 and 1.3.4, which fix the issue.
A vulnerability has been identified in the Apache IoTDB JDBC driver, versions 0.10.0 through 1.3.3 and 2.0.1-beta prior to 2.0.2. This issue involves the unauthorized exposure of sensitive information and the inappropriate logging of sensitive data. Users are advised to upgrade to version 2.0.2 or 1.3.4, both of which address this vulnerability.
Users should upgrade to Apache IoTDB JDBC driver version 2.0.2 or 1.3.4.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/05/14/3 | CVE | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/bj0ytxr5wg0c4jw8xm7rhfd8ogho0r91 | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-532 | Insertion of Sensitive Information into Log File | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-532 | Insertion of Sensitive Information into Log File | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache iotdb | >= 0.10.0, < 1.3.4 >= 2.0.1, < 2.0.2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 11, 2025 | Initial Analysis | [email protected] |
| May 19, 2025 | CVE Modified | CISA-ADP |
| May 14, 2025 | New CVE Received | [email protected] |
| May 14, 2025 | CVE Modified | CVE |