Описание
Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a filesystem.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Fuse 7 | camel-ignite | Not affected | ||
| Red Hat JBoss Fuse 6 | camel-ignite | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Important
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=1847145ignite: access to file system through predefined H2 SQL functions
EPSS
Процентиль: 89%
0.04667
Низкий
9.1 Critical
CVSS3
Связанные уязвимости
CVSS3: 9.1
nvd
больше 5 лет назад
Apache Ignite uses H2 database to build SQL distributed execution engine. H2 provides SQL functions which could be used by attacker to access to a filesystem.
EPSS
Процентиль: 89%
0.04667
Низкий
9.1 Critical
CVSS3