Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8p83-68cw-943f

Опубликовано: 16 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Apache Ignite communicates to an external PHP server where sensitive information is sent

Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do that the component communicates to an external PHP server (http://ignite.run) where it needs to send some system properties like Apache Ignite or Java version. Some of the properties might contain user sensitive information.

Пакеты

Наименование

org.apache.ignite:ignite-core

maven
Затронутые версииВерсия исправления

< 2.1

2.1

EPSS

Процентиль: 78%
0.0117
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
nvd
больше 8 лет назад

Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do that the component communicates to an external PHP server (http://ignite.run) where it needs to send some system properties like Apache Ignite or Java version. Some of the properties might contain user sensitive information.

EPSS

Процентиль: 78%
0.0117
Низкий

7.5 High

CVSS3

Дефекты

CWE-200