Severity: low 

Affected versions:

- Apache IoTDB 2.0.0 before 2.0.6
- Apache IoTDB 1.0.0 before 1.3.6

Description:

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 
vulnerability in Apache IoTDB.

This issue affects Apache IoTDB: from 2.0.0 before 2.0.6, from 1.0.0 before 
1.3.6.

Users are recommended to upgrade to version 1.3.6 and 2.0.6, which fixes the 
issue.

Credit:

qx (finder)

References:

https://iotdb.apache.org
https://www.cve.org/CVERecord?id=CVE-2025-55017

Reply via email to