CVE-2024-24780
14.05.2025, 11:15
Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who hasprivilege to create UDF can register malicious function fromuntrusted URI. This issue affects Apache IoTDB: from 1.0.0 before 1.3.4. Users are recommended to upgrade to version 1.3.4, which fixes the issue.
Vendor | Product | Version |
---|---|---|
apache | iotdb | 1.0.0 ≤ 𝑥 < 1.3.4 |
𝑥
= Vulnerable software versions