CVE-2025-64152: Apache IoTDB: Path Traversal Vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.0.0 before 1.3.6, from 2.0.0 before 2.0.7.
Users are recommended to upgrade to version 1.3.6 and 2.0.7, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache IoTDBto a version that resolves this vulnerability.Fixed in 1.3.6 - Upgrade
Upgrade
Apache IoTDBto a version that resolves this vulnerability.Fixed in 2.0.7
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64152?
CVE-2025-64152 has a critical severity rating of 9.1 according to the CVSS v3.1 system.
How do I fix CVE-2025-64152?
To resolve CVE-2025-64152, upgrade Apache IoTDB to version 1.3.6 or 2.0.7.
What is the main issue described in CVE-2025-64152?
CVE-2025-64152 describes a Path Traversal vulnerability that allows unauthorized access to restricted directories in Apache IoTDB.
Which versions of Apache IoTDB are affected by CVE-2025-64152?
CVE-2025-64152 affects Apache IoTDB versions from 1.0.0 before 1.3.6 and from 2.0.0 before 2.0.7.
What are the potential impacts of CVE-2025-64152?
Exploitation of CVE-2025-64152 could lead to unauthorized reading or manipulation of sensitive data due to improper path limitations.