Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI.
This issue affects Apache IoTDB: from 1.0.0 before 1.3.4.
Users are recommended to upgrade to version 1.3.4, which fixes the issue.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Jul 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache iotdb |
|
CPEs | cpe:2.3:a:apache:iotdb:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apache
Apache iotdb |
Wed, 14 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-94 | |
Metrics |
cvssV3_1
|
Wed, 14 May 2025 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 14 May 2025 11:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI. This issue affects Apache IoTDB: from 1.0.0 before 1.3.4. Users are recommended to upgrade to version 1.3.4, which fixes the issue. | |
Title | Apache IoTDB: Remote Code Execution with untrusted URI of User-defined function | |
References |
|

Status: PUBLISHED
Assigner: apache
Published: 2025-05-14T10:42:20.580Z
Updated: 2025-05-15T04:01:59.925Z
Reserved: 2024-01-30T10:43:03.969Z
Link: CVE-2024-24780

Updated: 2025-05-14T11:03:09.771Z

Status : Analyzed
Published: 2025-05-14T11:15:47.683
Modified: 2025-07-01T19:21:39.177
Link: CVE-2024-24780

No data.