QID 980937
QID 980937: Java (maven) Security Update for org.apache.ignite:ignite-core (GHSA-qcjv-wfcg-mmpr)
Apache Ignite 2.5 and earlier serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a specially prepared form of a serialized object to GridClientJdkMarshaller deserialization endpoint.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-qcjv-wfcg-mmpr for updates pertaining to this vulnerability.
Vendor References
- GHSA-qcjv-wfcg-mmpr -
github.com/advisories/GHSA-qcjv-wfcg-mmpr
CVEs related to QID 980937
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qcjv-wfcg-mmpr | org.apache.ignite:ignite-core |
|