Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI. This issue affects Apache IoTDB: from 1.0.0 before 1.3.4. Users are recommended to upgrade to version 1.3.4, which fixes the issue.
History

Wed, 14 May 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 14 May 2025 11:45:00 +0000

Type Values Removed Values Added
References

Wed, 14 May 2025 11:00:00 +0000

Type Values Removed Values Added
Description Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI. This issue affects Apache IoTDB: from 1.0.0 before 1.3.4. Users are recommended to upgrade to version 1.3.4, which fixes the issue.
Title Apache IoTDB: Remote Code Execution with untrusted URI of User-defined function
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2025-05-14T10:42:20.580Z

Updated: 2025-05-15T03:58:59.850Z

Reserved: 2024-01-30T10:43:03.969Z

Link: CVE-2024-24780

cve-icon Vulnrichment

Updated: 2025-05-14T11:03:09.771Z

cve-icon NVD

Status : Received

Published: 2025-05-14T11:15:47.683

Modified: 2025-05-14T14:15:25.263

Link: CVE-2024-24780

cve-icon Redhat

No data.