VDB

CVE-2018-8018

CVE-2018-8018 PUBLISHED

Reported by apache · Published July 19, 2018

In Apache Ignite before 2.4.8 and 2.5.x before 2.5.3, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a specially prepared form of a serialized object to GridClientJdkMarshaller deserialization endpoint.

Affected Products

VendorProductVersions
Apache Software FoundationApache Ignite2.5.x before 2.5.3, 2.4.x before 2.4.8
Apache Software FoundationApache Ignite2.4.x before 2.4.8, 2.5.x before 2.5.3, 2.4.x before 2.4.8
Mavenorg.apache.ignite:ignite-core0, 0

Timeline

  • Jul 19, 2018 CVE Published
  • Apr 14, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • May 8, 2023 EPSS Score
  • May 13, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›