Use of a Broken or Risky Cryptographic Algorithm
CVE-2019-0187
Summary
Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). The attacker can establish an RMI connection to a JMeter server using RemoteJMeterEngine and proceed with an attack using untrusted data deserialization. This only affects tests running in distributed mode. Note that versions before 4.0 are not able to encrypt traffic between the nodes nor authenticate the participating nodes. This issue affects versions prior to 5.1.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- HIGH
- HIGH
CWE-327 - Use of a Broken or Risky Cryptographic Algorithm
The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information.
References
Advisory Timeline
- Published