{"id":"CVE-2020-1952","aliases":["GHSA-wc6f-cjcp-cc33"],"url":"https://o3.security/vulnerability/CVE-2020-1952","summary":"Improper Certificate Validation in Apache IoTDB","details":"An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, clients could execute code remotely.","published":"2020-04-27T17:15:13.533Z","modified":"2026-07-09T01:06:49.784759Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.iotdb:iotdb-parent","fixedVersion":"0.9.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://lists.apache.org/thread.html/r3d2ff899ead64d2952fdc1fbb1f520ca42011ed2b4c7f786e921f6b9%40%3Cdev.iotdb.apache.org%3E"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T01:06:49.784759Z"}}