Description
In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4306 | In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code. |
Github GHSA |
GHSA-j7j7-g4ww-pxg5 | Missing certificate validation in Apache JMeter |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-17T03:02:25.926Z
Reserved: 2017-12-07T00:00:00.000Z
Link: CVE-2018-1287
No data.
Status : Modified
Published: 2018-02-14T14:29:00.210
Modified: 2024-11-21T03:59:33.020
Link: CVE-2018-1287
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA