CVE-2024-24780
Apache IoTDB: Remote Code Execution with untrusted URI of User-defined function
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI. This issue affects Apache IoTDB: from 1.0.0 before 1.3.4. Users are recommended to upgrade to version 1.3.4, which fixes the issue.
Vulnerabilidad de ejecución remota de código con URI no confiable de UDF en Apache IoTDB. El atacante con privilegios para crear UDF puede registrar una función maliciosa desde una URI no confiable. Este problema afecta a Apache IoTDB desde la versión 1.0.0 hasta la 1.3.4. Se recomienda actualizar a la versión 1.3.4, que soluciona el problema.
Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI. This issue affects Apache IoTDB: from 1.0.0 before 1.3.4. Users are recommended to upgrade to version 1.3.4, which fixes the issue.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-01-30 CVE Reserved
- 2025-05-14 CVE Published
- 2025-05-14 EPSS Updated
- 2025-05-15 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2025/05/14/2 |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://lists.apache.org/thread/xphtm98v3zsk9vlpfh481m1ry2ctxvmj | 2025-05-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Software Foundation Search vendor "Apache Software Foundation" | Apache IoTDB Search vendor "Apache Software Foundation" for product "Apache IoTDB" | >= 1.0.0 < 1.3.4 Search vendor "Apache Software Foundation" for product "Apache IoTDB" and version " >= 1.0.0 < 1.3.4" | en |
Affected
|