Apache JMeter Security Restriction Bypass Vulnerability (CVE-2018-1287)
Apache JMeter Security Restriction Bypass Vulnerability (CVE-2018-1287)
Release date:
Updated on:
Affected Systems:
Apache Group JMeter 3.x
Apache Group JMeter 2.x
Description:
Bugtraq id: 103068
CVE (CAN) ID: CVE-2018-1287
Apache JMeter is a Java-based stress testing tool developed by Apache.
Apache JMeter 2.x and 3.x versions. When only Distributed Test is used, the jmeter server binds the RMI Registry to the wildcard host, which allows remote attackers to access JMeterEngine and send unauthorized code.
<* Source: Brenden Meeder
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://www.apache.org/security/projects.html
Http://mail-archives.apache.org/mod_mbox/www-announce/201802.mbox/%3CCAH9fUpYsFx1%2Brwz1A%3Dmc7wAgbDHARyj1VrWNg41y9OySuL1mqw%40mail.gmail.com%3E
This article permanently updates link: https://www.bkjia.com/Linux/2018-03/151207.htm