PT-2018-11443 · Apache+1 · Apache Jmeter+1

Publicado

2018-02-14

·

Atualizado

2022-05-13

·

CVE-2018-1287

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache JMeter versions 2.X through 3.X
Description The issue arises when Apache JMeter is used in Distributed Test mode, which is RMI-based. In this scenario, the jmeter server binds the RMI Registry to a wildcard host, potentially allowing an attacker to access the JMeterEngine and send unauthorized code. This vulnerability is based on the architectural assumption that JMeter is operating on a 'safe' network where all users with access are considered trusted.
Recommendations For Apache JMeter versions 2.X through 3.X, consider restricting access to the RMI Registry to minimize the risk of exploitation, especially when operating in Distributed Test mode. As a temporary workaround, limit the network access to trusted users only, aligning with JMeter's architectural assumption of a 'safe' network.

Correção

Improper Verification of Cryptographic Signature

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1287
GHSA-J7J7-G4WW-PXG5

Produtos afetados

Apache Jmeter
Debian