Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j7j7-g4ww-pxg5

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Missing certificate validation in Apache JMeter

In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code. This only affect those running in Distributed mode.

In distributed mode, JMeter makes an architectural assumption that it is operating on a 'safe' network. i.e. everyone with access to the network is considered trusted.

Пакеты

Наименование

org.apache.jmeter:ApacheJMeter

maven
Затронутые версииВерсия исправления

< 4.0

4.0

EPSS

Процентиль: 88%
0.03352
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.

CVSS3: 9.8
nvd
больше 8 лет назад

In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.

CVSS3: 9.8
debian
больше 8 лет назад

In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI ba ...

EPSS

Процентиль: 88%
0.03352
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-347