Логотип exploitDog
bind:CVE-2018-1295
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-1295

Количество 3

Количество 3

redhat логотип

CVE-2018-1295

почти 8 лет назад

In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a specially prepared form of a serialized object to one of the deserialization endpoints of some Ignite components - discovery SPI, Ignite persistence, Memcached endpoint, socket steamer.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2018-1295

почти 8 лет назад

In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a specially prepared form of a serialized object to one of the deserialization endpoints of some Ignite components - discovery SPI, Ignite persistence, Memcached endpoint, socket steamer.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-chp4-rv79-68j3

больше 7 лет назад

Apache serialization mechanism does not have a list of classes allowed for serialization/deserialization

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2018-1295

In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a specially prepared form of a serialized object to one of the deserialization endpoints of some Ignite components - discovery SPI, Ignite persistence, Memcached endpoint, socket steamer.

CVSS3: 8.1
6%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-1295

In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a specially prepared form of a serialized object to one of the deserialization endpoints of some Ignite components - discovery SPI, Ignite persistence, Memcached endpoint, socket steamer.

CVSS3: 9.8
6%
Низкий
почти 8 лет назад
github логотип
GHSA-chp4-rv79-68j3

Apache serialization mechanism does not have a list of classes allowed for serialization/deserialization

CVSS3: 9.8
6%
Низкий
больше 7 лет назад

Уязвимостей на страницу