We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-24780

Apache IoTDB: Remote Code Execution with untrusted URI of User-defined function



Description

Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI. This issue affects Apache IoTDB: from 1.0.0 before 1.3.4. Users are recommended to upgrade to version 1.3.4, which fixes the issue.

Reserved 2024-01-30 | Published 2025-05-14 | Updated 2025-05-15 | Assigner apache

Problem types

Remote Code Execution with untrusted URI of User-defined function

Product status

Default status
unaffected

1.0.0 before 1.3.4
affected

Credits

Y4 tacker finder

Nbxiglk finder

References

lists.apache.org/thread/xphtm98v3zsk9vlpfh481m1ry2ctxvmj vendor-advisory

cve.org (CVE-2024-24780)

nvd.nist.gov (CVE-2024-24780)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-24780

Support options

Helpdesk Chat, Email, Knowledgebase