oss-sec mailing list archives

CVE-2025-48392: Apache IoTDB: DoS Vulnerability


From: Haonan Hou <haonan () apache org>
Date: Wed, 24 Sep 2025 06:34:58 +0000

Severity: moderate 

Affected versions:

- Apache IoTDB 1.3.3 through 1.3.4
- Apache IoTDB 2.0.1-beta through 2.0.4

Description:

A vulnerability in Apache IoTDB.

This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0.4.

Users are recommended to upgrade to version 2.0.5, which fixes the issue.

Credit:

yyjLF (finder)

References:

https://iotdb.apache.org
https://www.cve.org/CVERecord?id=CVE-2025-48392


Current thread: