ignite-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Denis Magda <dma...@apache.org>
Subject [CVE-2014-0114]: Apache Ignite is vulnerable to existing CVE-2014-0114
Date Fri, 01 Jun 2018 17:16:50 GMT
[CVE-2014-0114]: Apache Ignite is vulnerable to existing CVE-2014-0114

Severity: Important

Vendor: The Apache Software Foundation

Versions Affected: Apache Ignite 2.4 or earlier

An attacker can execute arbitrary code on Ignite nodes in the case when
Ignite classpath contains arbitrary vulnerable classes.

Apache Ignite used commons-beanutils-1.8.3.jar library which did not
suppress the class property, which allowed remote attackers to "manipulate"
the ClassLoader and execute arbitrary code via the class parameter, as
demonstrated by the passing of this parameter to the getClass method of the
ActionForm object in Struts 1.

•    All Ignite versions: make sure there are no vulnerable classes among
your custom code used in Apache Ignite.
•    Upgrade to Apache Ignite 2.5 or later version

Harendra Rai of NCR Corporation discovered the impact of the existing
vulnerability on Apache Ignite.

* https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0114

  • Unnamed multipart/alternative (inline, None, 0 bytes)
View raw message