CVE-2017-7686
Apache Ignite communicates to an external PHP server where sensitive information is sent
7.5
HIGH
CVSS 3.1
EPSS 1.2%
Description
Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do that the component communicates to an external PHP server (http://ignite.run) where it needs to send some system properties like Apache Ignite or Java version. Some of the properties might contain user sensitive information.
How to fix CVE-2017-7686
To remediate CVE-2017-7686, upgrade the affected package to a fixed version below.
- —upgrade to 2.1 or later
Is CVE-2017-7686 being exploited?
Low — EPSS is 1.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |