HarborGuard / CVE
Back to search
CRITICALCVE-2026-24015Published Modified CNA apache

CVE-2026-24015: Apache IoTDB: Insecure Default Configuration Vulnerability

A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.7 or 2.0.7, which fixes the issue.

Metrics

CVSS v3.1
9.8
Severity
CRITICAL
Fixed in
1.3.7
Affected Products
1

Fix available

1.3.72.0.7
Affected packages
  • Apache Software Foundation / Apache IoTDB
    < 1.3.7 (from 1.0.0) · < 2.0.7 (from 2.0.0)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H