QID 981125
QID 981125: Java (maven) Security Update for org.apache.ignite:ignite-core (GHSA-chp4-rv79-68j3)
In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a specially prepared form of a serialized object to one of the deserialization endpoints of some Ignite components - discovery SPI, Ignite persistence, Memcached endpoint, socket steamer.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-chp4-rv79-68j3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-chp4-rv79-68j3 -
github.com/advisories/GHSA-chp4-rv79-68j3
CVEs related to QID 981125
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-chp4-rv79-68j3 | org.apache.ignite:ignite-core |
|