CVE-2024-24780

Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI. This issue affects Apache IoTDB: from 1.0.0 before 1.3.4. Users are recommended to upgrade to version 1.3.4, which fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:iotdb:*:*:*:*:*:*:*:*

History

01 Jul 2025, 19:21

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-14 11:15

Updated : 2025-07-01 19:21


NVD link : CVE-2024-24780

Mitre link : CVE-2024-24780

CVE.ORG link : CVE-2024-24780


JSON object : View

Products Affected

apache

  • iotdb
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')