CVE-2025-26864: Apache IoTDB: Exposure of Sensitive Information in IoTDB OpenID Authentication
Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB.
This issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2.
Users are recommended to upgrade to version 1.3.4 and 2.0.2, which fix the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26864?
CVE-2025-26864 has been classified with a severity rating that indicates a moderate risk of exposure to sensitive information.
How do I fix CVE-2025-26864?
To fix CVE-2025-26864, users should upgrade Apache IoTDB to version 2.0.2 or later.
What systems are affected by CVE-2025-26864?
CVE-2025-26864 affects Apache IoTDB versions from 0.10.0 through 1.3.3 and any versions prior to 2.0.2.
What type of vulnerability is CVE-2025-26864?
CVE-2025-26864 is a vulnerability that involves the exposure of sensitive information to unauthorized actors and improper insertion of sensitive information into log files.
Is CVE-2025-26864 a critical vulnerability?
While not classified as critical, CVE-2025-26864 poses a significant risk due to the potential exposure of sensitive information.