GHSA-f4rq-f4j9-f6rm
CRITICALCVE-2024-24780Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI.
- Affected
- >= 1.0.0, < 1.3.4
- Fixed in
- 1.3.4
- Weakness
- CWE-94
- Published
- 2025-05-14
- Source
- github