CVE-2017-7686

Severity
7.5HIGH
EPSS
1.2%
top 21.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 28
Latest updateOct 16

Description

Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do that the component communicates to an external PHP server (http://ignite.run) where it needs to send some system properties like Apache Ignite or Java version. Some of the properties might contain user sensitive information.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDapache/ignite11 versions+10
CVEListV5apache_software_foundation/apache_ignite1.0.0-RC3 to 2.0

🔴Vulnerability Details

3
GHSA
Apache Ignite communicates to an external PHP server where sensitive information is sent2018-10-16
OSV
Apache Ignite communicates to an external PHP server where sensitive information is sent2018-10-16
CVEList
CVE-2017-7686: Apache Ignite 12017-06-28
CVE-2017-7686 (HIGH CVSS 7.5) | Apache Ignite 1.0.0-RC3 to 2.0 uses | cvebase.io