CVE-2024-24780

CWE-94Code Injection5 documents4 sources
Severity
9.8CRITICAL
EPSS
1.6%
top 18.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14

Description

Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI. This issue affects Apache IoTDB: from 1.0.0 before 1.3.4. Users are recommended to upgrade to version 1.3.4, which fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

NVDapache/iotdb1.0.01.3.4
PyPIapache-iotdb1.0.01.3.4
Mavenorg.apache.iotdb:iotdb-core1.0.01.3.4
CVEListV5apache_software_foundation/apache_iotdb1.0.01.3.4

🔴Vulnerability Details

4
OSV
CVE-2024-24780: Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB2025-05-14
GHSA
Apache IoTDB Vulnerable to Remote Code Execution2025-05-14
OSV
Apache IoTDB Vulnerable to Remote Code Execution2025-05-14
CVEList
Apache IoTDB: Remote Code Execution with untrusted URI of User-defined function2025-05-14
CVE-2024-24780 (CRITICAL CVSS 9.8) | Remote Code Execution with untruste | cvebase.io