In Apache JMeter 2.X and 3.X, when using Distributed Test only (RMI based), jmeter server binds RMI Registry to wildcard host. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.
{
"binaries": [
{
"binary_version": "2.11-5",
"binary_name": "jmeter"
},
{
"binary_version": "2.11-5",
"binary_name": "jmeter-apidoc"
},
{
"binary_version": "2.11-5",
"binary_name": "jmeter-ftp"
},
{
"binary_version": "2.11-5",
"binary_name": "jmeter-help"
},
{
"binary_version": "2.11-5",
"binary_name": "jmeter-http"
},
{
"binary_version": "2.11-5",
"binary_name": "jmeter-java"
},
{
"binary_version": "2.11-5",
"binary_name": "jmeter-jms"
},
{
"binary_version": "2.11-5",
"binary_name": "jmeter-junit"
},
{
"binary_version": "2.11-5",
"binary_name": "jmeter-ldap"
},
{
"binary_version": "2.11-5",
"binary_name": "jmeter-mail"
},
{
"binary_version": "2.11-5",
"binary_name": "jmeter-mongodb"
},
{
"binary_version": "2.11-5",
"binary_name": "jmeter-tcp"
}
]
}{
"binaries": [
{
"binary_version": "2.13-3",
"binary_name": "jmeter"
},
{
"binary_version": "2.13-3",
"binary_name": "jmeter-apidoc"
},
{
"binary_version": "2.13-3",
"binary_name": "jmeter-ftp"
},
{
"binary_version": "2.13-3",
"binary_name": "jmeter-help"
},
{
"binary_version": "2.13-3",
"binary_name": "jmeter-http"
},
{
"binary_version": "2.13-3",
"binary_name": "jmeter-java"
},
{
"binary_version": "2.13-3",
"binary_name": "jmeter-jms"
},
{
"binary_version": "2.13-3",
"binary_name": "jmeter-junit"
},
{
"binary_version": "2.13-3",
"binary_name": "jmeter-ldap"
},
{
"binary_version": "2.13-3",
"binary_name": "jmeter-mail"
},
{
"binary_version": "2.13-3",
"binary_name": "jmeter-mongodb"
},
{
"binary_version": "2.13-3",
"binary_name": "jmeter-tcp"
}
]
}{
"binaries": [
{
"binary_version": "2.13-4",
"binary_name": "jmeter"
},
{
"binary_version": "2.13-4",
"binary_name": "jmeter-apidoc"
},
{
"binary_version": "2.13-4",
"binary_name": "jmeter-ftp"
},
{
"binary_version": "2.13-4",
"binary_name": "jmeter-help"
},
{
"binary_version": "2.13-4",
"binary_name": "jmeter-http"
},
{
"binary_version": "2.13-4",
"binary_name": "jmeter-java"
},
{
"binary_version": "2.13-4",
"binary_name": "jmeter-jms"
},
{
"binary_version": "2.13-4",
"binary_name": "jmeter-junit"
},
{
"binary_version": "2.13-4",
"binary_name": "jmeter-ldap"
},
{
"binary_version": "2.13-4",
"binary_name": "jmeter-mail"
},
{
"binary_version": "2.13-4",
"binary_name": "jmeter-mongodb"
},
{
"binary_version": "2.13-4",
"binary_name": "jmeter-tcp"
}
]
}{
"binaries": [
{
"binary_version": "2.13-5",
"binary_name": "jmeter"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-apidoc"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-ftp"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-help"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-http"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-java"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-jms"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-junit"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-ldap"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-mail"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-mongodb"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-tcp"
}
]
}{
"binaries": [
{
"binary_version": "2.13-5",
"binary_name": "jmeter"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-apidoc"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-ftp"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-help"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-http"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-java"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-jms"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-junit"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-ldap"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-mail"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-mongodb"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-tcp"
}
]
}{
"binaries": [
{
"binary_version": "2.13-5",
"binary_name": "jmeter"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-apidoc"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-ftp"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-help"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-http"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-java"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-jms"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-junit"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-ldap"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-mail"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-mongodb"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-tcp"
}
]
}{
"binaries": [
{
"binary_version": "2.13-5",
"binary_name": "jmeter"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-apidoc"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-ftp"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-help"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-http"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-java"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-jms"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-junit"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-ldap"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-mail"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-mongodb"
},
{
"binary_version": "2.13-5",
"binary_name": "jmeter-tcp"
}
]
}