CVE-2024-24780
CRITICALApache IoTDB <1.3.4 - RCE
Title source: llmDescription
Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI. This issue affects Apache IoTDB: from 1.0.0 before 1.3.4. Users are recommended to upgrade to version 1.3.4, which fixes the issue.
Scores
CVSS v3
9.8
EPSS
0.0163
EPSS Percentile
81.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-94
Status
published
Affected Products (3)
apache/iotdb
< 1.3.4
org.apache.iotdb/iotdb-core
< 1.3.4Maven
pypi/apache-iotdb
< 1.3.4PyPI
Timeline
Published
May 14, 2025
Tracked Since
Feb 18, 2026