7.5

CVE-2017-7686

Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do that the component communicates to an external PHP server (http://ignite.run) where it needs to send some system properties like Apache Ignite or Java version. Some of the properties might contain user sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Ignite Version 1.0.0
Apache ≫ Ignite Version 1.0.0 Update rc3
Apache ≫ Ignite Version 1.1.0
Apache ≫ Ignite Version 1.2.0
Apache ≫ Ignite Version 1.3.0
Apache ≫ Ignite Version 1.4.0
Apache ≫ Ignite Version 1.5.0 Update b1
Apache ≫ Ignite Version 1.5.0 Update final
Apache ≫ Ignite Version 1.6.0
Apache ≫ Ignite Version 1.7.0
Apache ≫ Ignite Version 1.8.0
Apache ≫ Ignite Version 1.9.0
Apache ≫ Ignite Version 2.0.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.97% 0.855
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://apache-ignite-developers.2346864.n4.nabble.com/CVE-2017-7686-Apache-Ignite-Information-Disclosure-td19168.html
Third Party Advisory
Mitigation
http://www.securityfocus.com/bid/99292
Third Party Advisory
VDB Entry