Advisories for Maven/Org.apache.jmeter/ApacheJMeter package

2019

Deserialization of Untrusted Data

Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a jmeter-server using RemoteJMeterEngine and proceed with an attack using untrusted data deserialization. This only affect tests running in Distributed mode.

2018