https://seclists.org/oss-sec/2025/q2/142: CVE-2025-26864: Apache IoTDB: Exposuof Sensitive Information in IoTDB OpenID Authentication
Published May 14, 2025
·Updated
Affected Software
1 affected component
Apache IoTDB>=0.10.0<=1.3.3, <2.0.2
Frequently Asked Questions
1
What is the severity of CVE-2025-26864?
The severity of CVE-2025-26864 is classified as low.
2
Which versions of Apache IoTDB are affected by CVE-2025-26864?
Affected versions include Apache IoTDB from 0.10.0 through 1.3.3 and 2.0.1-beta before 2.0.2.
3
What type of vulnerability is CVE-2025-26864?
CVE-2025-26864 is a vulnerability related to the exposure of sensitive information in the OpenID authentication process.
4
How do I mitigate CVE-2025-26864?
Mitigation for CVE-2025-26864 involves upgrading to Apache IoTDB version 2.0.2 or later.
5
What impact does CVE-2025-26864 have on Apache IoTDB users?
CVE-2025-26864 may allow unauthorized access to sensitive information, affecting user data security.