Apache IoTDB OpenID Authentication Sensitive Information Exposure Vulnerability

Vulnerability

A vulnerability has been identified in the OpenIdAuthorizer component of Apache IoTDB, versions 0.10.0 through 1.3.3 and 2.0.1-beta prior to 2.0.2. This issue involves the exposure of sensitive information to unauthorized actors and the insertion of sensitive data into log files.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information and its improper logging, potentially allowing for further exploitation or privacy violations.

Remediation

Users are advised to upgrade to Apache IoTDB versions 1.3.4 or 2.0.2, both of which address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
2.5
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.