Unauthenticated RCE is possible when JMeter is used in distributed mode (-r or -R command line options). Attacker can establish a RMI connection to a jmeter-server using RemoteJMeterEngine and proceed with an attack using untrusted data deserialization. This only affect tests running in Distributed mode. Note that versions before 4.0 are not able to encrypt traffic between the nodes, nor authenticate the participating nodes so upgrade to JMeter 5.1 is also advised.
{
"binaries": [
{
"binary_name": "jmeter",
"binary_version": "2.11-5"
},
{
"binary_name": "jmeter-apidoc",
"binary_version": "2.11-5"
},
{
"binary_name": "jmeter-ftp",
"binary_version": "2.11-5"
},
{
"binary_name": "jmeter-help",
"binary_version": "2.11-5"
},
{
"binary_name": "jmeter-http",
"binary_version": "2.11-5"
},
{
"binary_name": "jmeter-java",
"binary_version": "2.11-5"
},
{
"binary_name": "jmeter-jms",
"binary_version": "2.11-5"
},
{
"binary_name": "jmeter-junit",
"binary_version": "2.11-5"
},
{
"binary_name": "jmeter-ldap",
"binary_version": "2.11-5"
},
{
"binary_name": "jmeter-mail",
"binary_version": "2.11-5"
},
{
"binary_name": "jmeter-mongodb",
"binary_version": "2.11-5"
},
{
"binary_name": "jmeter-tcp",
"binary_version": "2.11-5"
}
]
}{
"binaries": [
{
"binary_name": "jmeter",
"binary_version": "2.13-3"
},
{
"binary_name": "jmeter-apidoc",
"binary_version": "2.13-3"
},
{
"binary_name": "jmeter-ftp",
"binary_version": "2.13-3"
},
{
"binary_name": "jmeter-help",
"binary_version": "2.13-3"
},
{
"binary_name": "jmeter-http",
"binary_version": "2.13-3"
},
{
"binary_name": "jmeter-java",
"binary_version": "2.13-3"
},
{
"binary_name": "jmeter-jms",
"binary_version": "2.13-3"
},
{
"binary_name": "jmeter-junit",
"binary_version": "2.13-3"
},
{
"binary_name": "jmeter-ldap",
"binary_version": "2.13-3"
},
{
"binary_name": "jmeter-mail",
"binary_version": "2.13-3"
},
{
"binary_name": "jmeter-mongodb",
"binary_version": "2.13-3"
},
{
"binary_name": "jmeter-tcp",
"binary_version": "2.13-3"
}
]
}{
"binaries": [
{
"binary_name": "jmeter",
"binary_version": "2.13-4"
},
{
"binary_name": "jmeter-apidoc",
"binary_version": "2.13-4"
},
{
"binary_name": "jmeter-ftp",
"binary_version": "2.13-4"
},
{
"binary_name": "jmeter-help",
"binary_version": "2.13-4"
},
{
"binary_name": "jmeter-http",
"binary_version": "2.13-4"
},
{
"binary_name": "jmeter-java",
"binary_version": "2.13-4"
},
{
"binary_name": "jmeter-jms",
"binary_version": "2.13-4"
},
{
"binary_name": "jmeter-junit",
"binary_version": "2.13-4"
},
{
"binary_name": "jmeter-ldap",
"binary_version": "2.13-4"
},
{
"binary_name": "jmeter-mail",
"binary_version": "2.13-4"
},
{
"binary_name": "jmeter-mongodb",
"binary_version": "2.13-4"
},
{
"binary_name": "jmeter-tcp",
"binary_version": "2.13-4"
}
]
}{
"binaries": [
{
"binary_name": "jmeter",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-apidoc",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-ftp",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-help",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-http",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-java",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-jms",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-junit",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-ldap",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-mail",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-mongodb",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-tcp",
"binary_version": "2.13-5"
}
]
}{
"binaries": [
{
"binary_name": "jmeter",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-apidoc",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-ftp",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-help",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-http",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-java",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-jms",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-junit",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-ldap",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-mail",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-mongodb",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-tcp",
"binary_version": "2.13-5"
}
]
}{
"binaries": [
{
"binary_name": "jmeter",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-apidoc",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-ftp",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-help",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-http",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-java",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-jms",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-junit",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-ldap",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-mail",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-mongodb",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-tcp",
"binary_version": "2.13-5"
}
]
}{
"binaries": [
{
"binary_name": "jmeter",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-apidoc",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-ftp",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-help",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-http",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-java",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-jms",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-junit",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-ldap",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-mail",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-mongodb",
"binary_version": "2.13-5"
},
{
"binary_name": "jmeter-tcp",
"binary_version": "2.13-5"
}
]
}