https://seclists.org/oss-sec/2025/q2/140: CVE-2024-24780: Apache IoTDB: mote Code Execution with untrusted URI of User-defined function
Published May 14, 2025
·Updated
Affected Software
1 affected component
Apache IoTDB<1.3.4
Frequently Asked Questions
1
What is the severity of CVE-2024-24780?
The severity of CVE-2024-24780 is classified as moderate.
2
Which versions of Apache IoTDB are affected by CVE-2024-24780?
CVE-2024-24780 affects Apache IoTDB versions before 1.3.4.
3
What type of vulnerability is CVE-2024-24780?
CVE-2024-24780 is a remote code execution vulnerability that involves untrusted URIs of user-defined functions.
4
How do I fix CVE-2024-24780?
To fix CVE-2024-24780, upgrade Apache IoTDB to version 1.3.4 or later.
5
What is the risk associated with CVE-2024-24780?
The risk associated with CVE-2024-24780 includes an attacker gaining the ability to execute code remotely by exploiting untrusted URI registrations.