PT-2025-6710 · Apache · Apache Ignite
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache Ignite versions 2.6.0 through 2.17.0
Description
The vulnerability could be exploited if an attacker manually crafts an Ignite message containing a vulnerable object whose class is present in the Ignite server classpath and sends it to Ignite server endpoints. Deserialization of such a message by the Ignite server may result in the execution of arbitrary code on the Apache Ignite server side. It is estimated that 60% of deployments are unpatched, leaving sensitive data at risk.
Recommendations
For Apache Ignite versions 2.6.0 through 2.17.0, upgrade to version 2.17.0 or later to mitigate the risk of remote code execution. As a temporary workaround, consider restricting access to Ignite server endpoints to minimize the risk of exploitation.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Ignite