Apache iotdb是美国Apache基金会开源的一款物联网数据库。 Apache IoTDB 2.0.0版本至2.0.6之前版本和1.0.0版本至1.3.6之前版本存在路径遍历漏洞,该漏洞源于对路径名限制不当,容易受到路径遍历攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache IoTDB | 2.0.0< 2.0.6 |
affected |
1.0.0< 1.3.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache IoTDB | 2.0.0 ~ 2.0.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49486 | Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing PROT | |
| CVE-2026-57914 | Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures | |
| CVE-2026-57915 | Apache Kerby: Kerberos Pre-Authentication Bypass | |
| CVE-2025-64152 | Apache IoTDB: Path Traversal Vulnerability |
No comments yet