Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gp98-hfvm-2r4x

Опубликовано: 14 мая 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 7.5

Описание

Apache IoTDB JDBC Driver Discloses Sensitive Information via Log Files

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver.

This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2.

Users are recommended to upgrade to version 2.0.2 and 1.3.4, which fix the issue.

Пакеты

Наименование

org.apache.iotdb:iotdb-jdbc

maven
Затронутые версииВерсия исправления

>= 0.10.0, < 1.3.4

1.3.4

Наименование

org.apache.iotdb:iotdb-jdbc

maven
Затронутые версииВерсия исправления

>= 2.0.1-beta, < 2.0.2

2.0.2

EPSS

Процентиль: 32%
0.00123
Низкий

6.9 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-200
CWE-532

Связанные уязвимости

CVSS3: 7.5
nvd
9 месяцев назад

Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver. This issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2. Users are recommended to upgrade to version 2.0.2 and 1.3.4, which fix the issue.

EPSS

Процентиль: 32%
0.00123
Низкий

6.9 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-200
CWE-532