org.apache.ignite:ignite-core
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.ignite:ignite-corepage 1 of 1
- CVE-2016-6805MEDIUMCVSS 5.9EG 5.9✓ Fixed in 1.92017-04-07
vulnerable: 1.0.0 ... 1.8.0 (12 versions)
Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents.
- CVE-2017-7686HIGHCVSS 7.5EG 7.5✓ Fixed in 2.12017-06-28
vulnerable: 1.0.0 ... 2.0.0 (14 versions)
Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do that the component communicates to an exte…
- CVE-2018-1295CRITICALCVSS 9.8✓ Fixed in 2.42018-04-02
vulnerable: 1.0.0 ... 2.3.0 (17 versions)
In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite …
- CVE-2018-8018CRITICALCVSS 9.8✓ Fixed in 2.62018-07-20
vulnerable: 1.0.0 ... 2.5.0 (19 versions)
In Apache Ignite before 2.4.8 and 2.5.x before 2.5.3, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes a…
- CVE-2020-1963CRITICALCVSS 9.1EG 9.1✓ Fixed in 2.8.12020-06-03
vulnerable: 1.0.0 ... 2.8.0 (24 versions)
Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a filesystem.
Check whether org.apache.ignite:ignite-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.ignite:ignite-core CVEs against the assets you own.
Start Free Scan →