PT-2019-11181 · Apache+1 · Apache Jmeter+1
Published
2019-03-06
·
Updated
2020-08-24
·
CVE-2019-0187
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Apache JMeter versions prior to 5.1
Description:
The issue allows for unauthenticated remote code execution when JMeter is used in distributed mode. An attacker can establish a connection to a jmeter-server and proceed with an attack using untrusted data deserialization. This issue only affects tests running in distributed mode. It is also noted that versions before 4.0 lack the ability to encrypt traffic between nodes and authenticate participating nodes.
Recommendations:
For versions prior to 5.1, upgrade to JMeter 5.1 to resolve the issue. As a temporary workaround, consider restricting the use of distributed mode until the upgrade is applied. Additionally, restricting access to the RemoteJMeterEngine can help minimize the risk of exploitation.
Fix
RCE
Use of a Broken Cryptographic Algorithm
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Jmeter
Debian