Vulnerability Description
Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a filesystem.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Ignite | <= 2.8.0 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2020/06/03/2Mailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r119024ef71c8d39f952df0950a275d09714715179a
- https://lists.apache.org/thread.html/r1933faf8a26c431f38a5f8dbbfab80254454e54e33Mailing ListVendor Advisory
- https://lists.apache.org/thread.html/rd43ae18588fd7bdb375be63bc95a651aab319ced63
- https://lists.apache.org/thread.html/rdf37011b92a31a67c299ff45655e2638f194fc814e
- https://lists.apache.org/thread.html/rdf37011b92a31a67c299ff45655e2638f194fc814e
- https://lists.apache.org/thread.html/re7b43cf8333ee30b6589e465f72a6ed4a082222612
- https://lists.apache.org/thread.html/re7b43cf8333ee30b6589e465f72a6ed4a082222612
- https://lists.apache.org/thread.html/rf032a13a4711f88c0a2c0734eecbee1026cc1b6cde
- https://www.oracle.com/security-alerts/cpujan2022.htmlNot ApplicableThird Party Advisory
- http://www.openwall.com/lists/oss-security/2020/06/03/2Mailing ListThird Party Advisory
- https://lists.apache.org/thread.html/r119024ef71c8d39f952df0950a275d09714715179a
- https://lists.apache.org/thread.html/r1933faf8a26c431f38a5f8dbbfab80254454e54e33Mailing ListVendor Advisory
- https://lists.apache.org/thread.html/rd43ae18588fd7bdb375be63bc95a651aab319ced63
- https://lists.apache.org/thread.html/rdf37011b92a31a67c299ff45655e2638f194fc814e
FAQ
What is CVE-2020-1963?
CVE-2020-1963 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a filesystem.
How severe is CVE-2020-1963?
CVE-2020-1963 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-1963?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Ignite.