CVE-2017-7686
published 2017-06-28CVE-2017-7686: Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug…
PriorityP341high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
2.97%
85.6th percentile
Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do that the component communicates to an external PHP server (http://ignite.run) where it needs to send some system properties like Apache Ignite or Java version. Some of the properties might contain user sensitive information.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ignite | — | — |
| apache | ignite | — | — |
| apache | ignite | — | — |
| apache | ignite | — | — |
| apache | ignite | — | — |
| apache | ignite | — | — |
| apache | ignite | — | — |
| apache | ignite | — | — |
| apache | ignite | — | — |
| apache | ignite | — | — |
| apache | ignite | — | — |
| apache_software_foundation | apache_ignite | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Ignite communicates to an external PHP server where sensitive information is sent
ghsa·2018-10-16
CVE-2017-7686 [HIGH] CWE-200 Apache Ignite communicates to an external PHP server where sensitive information is sent
Apache Ignite communicates to an external PHP server where sensitive information is sent
Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do that the component communicates to an external PHP server (http://ignite.run) where it needs to send some system properties like Apache Ignite or Java version. Some of the properties might contain user sensitive information.
OSV
Apache Ignite communicates to an external PHP server where sensitive information is sent
osv·2018-10-16
CVE-2017-7686 [HIGH] Apache Ignite communicates to an external PHP server where sensitive information is sent
Apache Ignite communicates to an external PHP server where sensitive information is sent
Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do that the component communicates to an external PHP server (http://ignite.run) where it needs to send some system properties like Apache Ignite or Java version. Some of the properties might contain user sensitive information.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://apache-ignite-developers.2346864.n4.nabble.com/CVE-2017-7686-Apache-Ignite-Information-Disclosure-td19168.htmlhttp://www.securityfocus.com/bid/99292http://apache-ignite-developers.2346864.n4.nabble.com/CVE-2017-7686-Apache-Ignite-Information-Disclosure-td19168.htmlhttp://www.securityfocus.com/bid/99292
2017-06-28
Published