What the vulnerability does

01Description

nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing arbitrary code via RMI registry by remote attacker.

Key dates

02Disclosure timeline

March 7, 2024 CVE published
August 5, 2024 Record updated