Jmeter Apache Jmeter

Do you want an email whenever new security vulnerabilities are reported in Apache Jmeter?

By the Year

In 2024 there have been 0 vulnerabilities in Apache Jmeter . Jmeter did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 0 0.00
2020 0 0.00
2019 1 9.80
2018 2 9.80

It may take a day or so for new Jmeter vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apache Jmeter Security Vulnerabilities

Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options)

CVE-2019-0187 9.8 - Critical - March 06, 2019

Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a jmeter-server using RemoteJMeterEngine and proceed with an attack using untrusted data deserialization. This only affect tests running in Distributed mode. Note that versions before 4.0 are not able to encrypt traffic between the nodes, nor authenticate the participating nodes so upgrade to JMeter 5.1 is also advised.

Use of a Broken or Risky Cryptographic Algorithm

In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host

CVE-2018-1287 9.8 - Critical - February 14, 2018

In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.

When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection

CVE-2018-1297 9.8 - Critical - February 13, 2018

When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.

Cleartext Transmission of Sensitive Information

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Apache Jmeter or by Apache? Click the Watch button to subscribe.

Apache
Vendor

Apache Jmeter
Product

subscribe