Apache / Jmeter
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-21348 | XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos) | HIGH | 7.5 | Mar 22, 2021 |
| CVE-2021-21349 | A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or… | HIGH | 8.6 | Mar 22, 2021 |
| CVE-2021-21350 | XStream is vulnerable to an Arbitrary Code Execution attack | CRITICAL | 9.8 | Mar 22, 2021 |
| CVE-2021-21351 | XStream is vulnerable to an Arbitrary Code Execution attack | CRITICAL | 9.1 | Mar 22, 2021 |
| CVE-2021-21341 | XStream can cause a Denial of Service | HIGH | 7.5 | Mar 22, 2021 |
| CVE-2021-21342 | A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or… | CRITICAL | 9.1 | Mar 22, 2021 |
| CVE-2021-21343 | XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights | HIGH | 7.5 | Mar 22, 2021 |
| CVE-2021-21344 | XStream is vulnerable to an Arbitrary Code Execution attack | CRITICAL | 9.8 | Mar 22, 2021 |
| CVE-2021-21345 | XStream is vulnerable to a Remote Command Execution attack | CRITICAL | 9.9 | Mar 22, 2021 |
| CVE-2021-21346 | XStream is vulnerable to an Arbitrary Code Execution attack | CRITICAL | 9.8 | Mar 22, 2021 |
| CVE-2021-21347 | XStream is vulnerable to an Arbitrary Code Execution attack | CRITICAL | 9.8 | Mar 22, 2021 |
| CVE-2019-0187 | Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a jmeter-se… | CRITICAL | 9.8 | Mar 6, 2019 |
| CVE-2018-1287 | In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to… | CRITICAL | 9.8 | Feb 14, 2018 |
| CVE-2018-1297 | When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterE… | CRITICAL | 9.8 | Feb 13, 2018 |
Showing 1 to 14 of 14 CVEs