HomeDefault status
unaffected
1.0.0 (semver) before 1.3.7
affected
2.0.0 (semver) before 2.0.7
affected
Description
Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.7 or 2.0.7, which fixes the issue.
Problem types
CWE-20 Improper Input Validation
Product status
1.0.0 (semver) before 1.3.7
2.0.0 (semver) before 2.0.7
Credits
Yongzhi Liu of Tencent YunDing Security Lab
References
www.openwall.com/lists/oss-security/2026/03/09/4
lists.apache.org/thread/vopgv6y2ccw403b0zv7rvojjrh7x1j5p