Information Disclosure Vulnerability in Apache Ignite by Apache
CVE-2017-7686
7.5HIGH
Summary
The vulnerability in Apache Ignite arises from its update notifier component, which communicates with an external server to inform users about new releases and enhancements. This communication can inadvertently reveal sensitive user information, such as system properties, including the version of Apache Ignite and Java being used. This exposure poses a risk as it may allow unauthorized access to delicate user data.
Affected Version(s)
Apache Ignite 1.0.0-RC3 to 2.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved