PT-2018-11443 · Apache+1 · Apache Jmeter+1
Publicado
2018-02-14
·
Atualizado
2022-05-13
·
CVE-2018-1287
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache JMeter versions 2.X through 3.X
Description
The issue arises when Apache JMeter is used in Distributed Test mode, which is RMI-based. In this scenario, the jmeter server binds the RMI Registry to a wildcard host, potentially allowing an attacker to access the JMeterEngine and send unauthorized code. This vulnerability is based on the architectural assumption that JMeter is operating on a 'safe' network where all users with access are considered trusted.
Recommendations
For Apache JMeter versions 2.X through 3.X, consider restricting access to the RMI Registry to minimize the risk of exploitation, especially when operating in Distributed Test mode. As a temporary workaround, limit the network access to trusted users only, aligning with JMeter's architectural assumption of a 'safe' network.
Correção
Improper Verification of Cryptographic Signature
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache Jmeter
Debian