CVE-2019-0187: Critical severity Apache JMeter vulnerability
Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a jmeter-server using RemoteJMeterEngine and proceed with an attack using untrusted data deserialization. This only affect tests running in Distributed mode. Note that versions before 4.0 are not able to encrypt traffic between the nodes, nor authenticate the participating nodes so upgrade to JMeter 5.1 is also advised.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0187?
CVE-2019-0187 is classified as a critical severity vulnerability due to its potential for unauthenticated remote code execution.
How do I fix CVE-2019-0187?
To fix CVE-2019-0187, it is recommended to upgrade Apache JMeter to version 5.1 or later.
Who is affected by CVE-2019-0187?
CVE-2019-0187 affects users of Apache JMeter versions 4.0 and 5.0 when running in distributed mode.
What type of attack can CVE-2019-0187 facilitate?
CVE-2019-0187 can facilitate an unauthenticated remote code execution attack using untrusted data deserialization.
Is authentication required to exploit CVE-2019-0187?
No, CVE-2019-0187 allows for exploitation without authentication, making it particularly dangerous.