PT-2019-11181 · Apache+1 · Apache Jmeter+1

Published

2019-03-06

·

Updated

2020-08-24

·

CVE-2019-0187

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Apache JMeter versions prior to 5.1
Description: The issue allows for unauthenticated remote code execution when JMeter is used in distributed mode. An attacker can establish a connection to a jmeter-server and proceed with an attack using untrusted data deserialization. This issue only affects tests running in distributed mode. It is also noted that versions before 4.0 lack the ability to encrypt traffic between nodes and authenticate participating nodes.
Recommendations: For versions prior to 5.1, upgrade to JMeter 5.1 to resolve the issue. As a temporary workaround, consider restricting the use of distributed mode until the upgrade is applied. Additionally, restricting access to the RemoteJMeterEngine can help minimize the risk of exploitation.

Fix

RCE

Use of a Broken Cryptographic Algorithm

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-0187
GHSA-WG37-7MRV-CFWM

Affected Products

Apache Jmeter
Debian