📦 Iotdb

by Apache

🔍 What is Iotdb?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-24780

CRITICAL CVSS 9.8 May 14, 2025

This vulnerability allows attackers with UDF creation privileges in Apache IoTDB to execute arbitrary code by registering malicious functions from untrusted URIs. It affects all Apache IoTDB installat...

CVE-2023-46226

CRITICAL CVSS 9.8 Jan 15, 2024

CVE-2023-46226 is a critical remote code execution vulnerability in Apache IoTDB that allows attackers to execute arbitrary code on affected systems. This affects all Apache IoTDB installations runnin...

CVE-2023-51656

CRITICAL CVSS 9.8 Dec 21, 2023

This CVE describes a deserialization vulnerability in Apache IoTDB that allows attackers to execute arbitrary code by sending malicious serialized data. It affects all users running Apache IoTDB versi...

CVE-2023-24831

CRITICAL CVSS 9.8 Apr 17, 2023

CVE-2023-24831 is an authentication bypass vulnerability in Apache IoTDB Grafana Connector that allows attackers to log in without proper credentials. This affects all systems running IoTDB Grafana Co...

CVE-2025-48392

HIGH CVSS 7.5 Sep 24, 2025

This vulnerability in Apache IoTDB is an uncontrolled resource consumption issue (CWE-400) that could allow attackers to cause denial of service. It affects IoTDB versions 1.3.3 through 1.3.4 and 2.0....

CVE-2025-26864

HIGH CVSS 7.5 May 14, 2025

Apache IoTDB's OpenIdAuthorizer component logs sensitive authentication information, potentially exposing credentials or tokens to unauthorized actors. This affects all users running vulnerable versio...