CVE-2024-24780: Apache IoTDB: Remote Code Execution with untrusted URI of User-defined function
Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI.
This issue affects Apache IoTDB: from 1.0.0 before 1.3.4.
Users are recommended to upgrade to version 1.3.4, which fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24780?
CVE-2024-24780 is classified as a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-24780?
To address CVE-2024-24780, users should upgrade Apache IoTDB to the latest version 1.3.4 or later.
What type of vulnerability is CVE-2024-24780?
CVE-2024-24780 is a remote code execution vulnerability associated with untrusted URI handling in user-defined functions (UDF).
Which versions of Apache IoTDB are affected by CVE-2024-24780?
CVE-2024-24780 affects Apache IoTDB versions from 1.0.0 up to, but not including, 1.3.4.
Can attackers exploit CVE-2024-24780 without authentication?
Attackers need privileges to create UDFs in order to exploit CVE-2024-24780.