Skip to main content

Use of a Broken or Risky Cryptographic Algorithm

CVE-2019-0187

Severity High
Score 9.8/10

Summary

Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). The attacker can establish an RMI connection to a JMeter server using RemoteJMeterEngine and proceed with an attack using untrusted data deserialization. This only affects tests running in distributed mode. Note that versions before 4.0 are not able to encrypt traffic between the nodes nor authenticate the participating nodes. This issue affects versions prior to 5.1.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • HIGH

CWE-327 - Use of a Broken or Risky Cryptographic Algorithm

The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information.

Advisory Timeline

  • Published