Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without sufficient validation. If the internal DataNode RPC port is exposed to an untrusted network, an attacker may use path traversal sequences in the JAR name to write files outside the intended Trigger installation directory. This could allow arbitrary file write with the permissions of the IoTDB process.
This issue affects Apache IoTDB: from 1.3.3 before 2.0.8.
Users are recommended to upgrade to version 2.0.8, which fixes the issue.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/38298f803gb5j9nlhf0l9zkf34o90h3m | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/07/06/12 | Mailing List Third Party Advisory |
Configurations
History
07 Jul 2026, 17:49
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Apache
Apache iotdb |
|
| CPE | cpe:2.3:a:apache:iotdb:*:*:*:*:*:*:*:* | |
| References | () https://lists.apache.org/thread/38298f803gb5j9nlhf0l9zkf34o90h3m - Mailing List, Vendor Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/07/06/12 - Mailing List, Third Party Advisory |
06 Jul 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
06 Jul 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
06 Jul 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-06 09:16
Updated : 2026-07-07 17:49
NVD link : CVE-2026-24014
Mitre link : CVE-2026-24014
CVE.ORG link : CVE-2026-24014
JSON object : View
Products Affected
apache
- iotdb
