Junglewise Threat Intelligence

CVE-2025-48459: Apache IoTDB insecure deserialization in external input processing

CVE-2025-48459 · Severity: medium · CVSS 5.3 · Published 2025-09-24

Technologies: Apache IoTDB, Apache Software Foundation IoTDB. Vendors: Apache, PyPI, Apache Software Foundation, Maven.

Executive brief

Apache IoTDB is a high-performance database designed for managing large amounts of Internet of Things (IoT) data. A security flaw allows attackers to send malicious data that the system processes without proper checks, potentially allowing them to take control of the server or access sensitive information. This could lead to unauthorized data modification or a complete compromise of the database service.

Technical details

Apache IoTDB (versions 1.0.0 to 2.0.4) fails to sufficiently validate external inputs during deserialization (CWE-502). An unauthenticated attacker can send specially crafted serialized objects over the network to vulnerable endpoints. If a compatible gadget chain is present in the application's classpath, this can result in remote code execution (RCE) or significant integrity and confidentiality loss. The vulnerability is addressed in version 2.0.5 by implementing stricter validation or sanitization of serialized payloads.

Affected products

  • Apache IoTDB >= 1.0.0, < 2.0.5

Timeline

  • 2025-09-24: disclosed
  • 2025-09-24: advisory
  • 2025-09-24: patched: Fixed in version 2.0.5

References

Related threats