漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache Ignite: Possible RCE when deserializing incoming messages by the server node
Vulnerability Description
In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerability could be exploited if an attacker manually crafts an Ignite message containing a vulnerable object whose class is present in the Ignite server classpath and sends it to Ignite server endpoints. Deserialization of such a message by the Ignite server may result in the execution of arbitrary code on the Apache Ignite server side.
CVSS Information
N/A
Vulnerability Type
可信数据的反序列化
Vulnerability Title
Apache Ignite 安全漏洞
Vulnerability Description
Apache Ignite是美国阿帕奇(Apache)基金会的一套高性能、集成化和分布式的用于大规模的数据集处理的内存计算和事务管理平台。 Apache Ignite 2.6.0版本至2.17.0之前版本存在安全漏洞,该漏洞源于某些Ignite端点会忽略已配置的类序列化过滤器,可能会导致在服务器端执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A