Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-7686


Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do that the component communicates to an external PHP server (http://ignite.run) where it needs to send some system properties like Apache Ignite or Java version. Some of the properties might contain user sensitive information.


Published

2017-06-28T13:29:00.217

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache ignite 1.0.0 Yes
Application apache ignite 1.0.0 Yes
Application apache ignite 1.1.0 Yes
Application apache ignite 1.2.0 Yes
Application apache ignite 1.3.0 Yes
Application apache ignite 1.4.0 Yes
Application apache ignite 1.5.0 Yes
Application apache ignite 1.5.0 Yes
Application apache ignite 1.6.0 Yes
Application apache ignite 1.7.0 Yes
Application apache ignite 1.8.0 Yes
Application apache ignite 1.9.0 Yes
Application apache ignite 2.0.0 Yes

References