CVE-2025-48392: Apache IoTDB: DoS Vulnerability
A vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0.4.
Users are recommended to upgrade to version 2.0.5, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.iotdb:iotdb-coreto a version that resolves this vulnerability.Fixed in 2.0.5 - Upgrade
Upgrade
Apache IoTDBto a version that resolves this vulnerability.Fixed in 2.0.5
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48392?
The severity of CVE-2025-48392 is reportedly significant as it affects multiple versions of Apache IoTDB.
How do I fix CVE-2025-48392?
To fix CVE-2025-48392, upgrade to Apache IoTDB version 2.0.5 or later.
Which versions of Apache IoTDB are affected by CVE-2025-48392?
CVE-2025-48392 affects Apache IoTDB versions from 1.3.3 to 1.3.4 and 2.0.1-beta to 2.0.4.
What products are impacted by CVE-2025-48392?
CVE-2025-48392 impacts the Apache IoTDB product.
Is there a recommended action for users regarding CVE-2025-48392?
Yes, users are strongly recommended to upgrade to version 2.0.5 to mitigate the risk associated with CVE-2025-48392.