CVE-2025-55017: Apache IoTDB: Path Traversal Vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 2.0.0 before 2.0.6, from 1.0.0 before 1.3.6.
Users are recommended to upgrade to version 1.3.6 and 2.0.6, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache IoTDBto a version that resolves this vulnerability.Fixed in 1.3.6Patch CVE-2025-55017 - Upgrade
Upgrade
Apache IoTDBto a version that resolves this vulnerability.Fixed in 2.0.6Patch CVE-2025-55017
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55017?
CVE-2025-55017 has a critical severity rating of 9.1.
How do I fix CVE-2025-55017?
To fix CVE-2025-55017, users should upgrade to Apache IoTDB version 1.3.6 or 2.0.6.
What type of vulnerability is CVE-2025-55017?
CVE-2025-55017 is a Path Traversal vulnerability affecting Apache IoTDB.
Which versions of Apache IoTDB are affected by CVE-2025-55017?
CVE-2025-55017 affects Apache IoTDB versions from 2.0.0 before 2.0.6 and from 1.0.0 before 1.3.6.
What impact does CVE-2025-55017 have on Apache IoTDB?
CVE-2025-55017 can lead to unauthorized file access due to improper limitation of a pathname.