🔐 CVE Alert

CVE-2024-24780

CRITICAL 9.8

Apache IoTDB: Remote Code Execution with untrusted URI of User-defined function

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI. This issue affects Apache IoTDB: from 1.0.0 before 1.3.4. Users are recommended to upgrade to version 1.3.4, which fixes the issue.

Vendor apache software foundation
Product apache iotdb
Published May 14, 2025
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache iotdb

Be the first to know when new critical vulnerabilities affecting apache software foundation apache iotdb are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache IoTDB
1.0.0 < 1.3.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread/xphtm98v3zsk9vlpfh481m1ry2ctxvmj openwall.com: http://www.openwall.com/lists/oss-security/2025/05/14/2

Credits

Y4 tacker Nbxiglk