Severity: low
Affected versions:
- Apache IoTDB 1.0.0 before 1.3.6
- Apache IoTDB 2.0.0 before 2.0.7
Description:
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.0.0 before 1.3.6, from 2.0.0 before
2.0.7.
Users are recommended to upgrade to version 1.3.6 and 2.0.7, which fixes the
issue.
Credit:
Yan Nan (Detecon Security Lab) (finder)
References:
https://iotdb.apache.org
https://www.cve.org/CVERecord?id=CVE-2025-64152