This issue affects Apache IoTDB: from 1.0.0 before 1.3.4.
Users are recommended to upgrade to version 1.3.4, which fixes the issue.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-22158 | Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI. This issue affects Apache IoTDB: from 1.0.0 before 1.3.4. Users are recommended to upgrade to version 1.3.4, which fixes the issue. |
Github GHSA |
GHSA-f4rq-f4j9-f6rm | Apache IoTDB Vulnerable to Remote Code Execution |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 01 Jul 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache iotdb |
|
| CPEs | cpe:2.3:a:apache:iotdb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Apache
Apache iotdb |
Wed, 14 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Wed, 14 May 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 14 May 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI. This issue affects Apache IoTDB: from 1.0.0 before 1.3.4. Users are recommended to upgrade to version 1.3.4, which fixes the issue. | |
| Title | Apache IoTDB: Remote Code Execution with untrusted URI of User-defined function | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-05-15T04:01:59.925Z
Reserved: 2024-01-30T10:43:03.969Z
Link: CVE-2024-24780
Updated: 2025-05-14T11:03:09.771Z
Status : Analyzed
Published: 2025-05-14T11:15:47.683
Modified: 2025-07-01T19:21:39.177
Link: CVE-2024-24780
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA