Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j7j7-g4ww-pxg5

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Missing certificate validation in Apache JMeter

In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code. This only affect those running in Distributed mode.

In distributed mode, JMeter makes an architectural assumption that it is operating on a 'safe' network. i.e. everyone with access to the network is considered trusted.

Пакеты

Наименование

org.apache.jmeter:ApacheJMeter

maven
Затронутые версииВерсия исправления

< 4.0

4.0

EPSS

Процентиль: 83%
0.01876
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.

CVSS3: 9.8
nvd
почти 8 лет назад

In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.

CVSS3: 9.8
debian
почти 8 лет назад

In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI ba ...

EPSS

Процентиль: 83%
0.01876
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-347