PT-2025-6710 · Apache · Apache Ignite
Alex Plehanov
+2
·
Published
2025-02-14
·
Updated
2025-07-14
·
CVE-2024-52577
CVSS v3.1
10
Critical
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Ignite versions 2.6.0 through 2.17.0
Description
The vulnerability could be exploited if an attacker manually crafts an Ignite message containing a vulnerable object whose class is present in the Ignite server classpath and sends it to Ignite server endpoints. Deserialization of such a message by the Ignite server may result in the execution of arbitrary code on the Apache Ignite server side. It is estimated that 60% of deployments are unpatched, leaving sensitive data at risk.
Recommendations
For Apache Ignite versions 2.6.0 through 2.17.0, upgrade to version 2.17.0 or later to mitigate the risk of remote code execution. As a temporary workaround, consider restricting access to Ignite server endpoints to minimize the risk of exploitation.
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Ignite