Vulnerability Description
Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do that the component communicates to an external PHP server (http://ignite.run) where it needs to send some system properties like Apache Ignite or Java version. Some of the properties might contain user sensitive information.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Ignite | 1.0.0 |
Related Weaknesses (CWE)
References
- http://apache-ignite-developers.2346864.n4.nabble.com/CVE-2017-7686-Apache-IgnitMitigationThird Party Advisory
- http://www.securityfocus.com/bid/99292Third Party AdvisoryVDB Entry
- http://apache-ignite-developers.2346864.n4.nabble.com/CVE-2017-7686-Apache-IgnitMitigationThird Party Advisory
- http://www.securityfocus.com/bid/99292Third Party AdvisoryVDB Entry
FAQ
What is CVE-2017-7686?
CVE-2017-7686 is a vulnerability with a CVSS score of 7.5 (HIGH). Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do tha...
How severe is CVE-2017-7686?
CVE-2017-7686 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7686?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Ignite.