Apache / Ignite
9 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-48977 | Apache Ignite: REST HTTP arbitrary file read vulnerability | HIGH | 8.5 | May 28, 2026 |
| CVE-2024-52577 | Apache Ignite: Possible RCE when deserializing incoming messages by the server node | CRITICAL | 9.5 | Feb 14, 2025 |
| CVE-2021-28163 | jetty: Symlink directory exposes webapp directory contents | LOW | 2.7 | Apr 1, 2021 |
| CVE-2020-1963 | ignite: access to file system through predefined H2 SQL functions | CRITICAL | 9.1 | Jun 3, 2020 |
| CVE-2018-8018 | ignite: Improper deserialization allows for code execution via GridClientJdkMarshaller endpoint | CRITICAL | 9.8 | Jul 19, 2018 |
| CVE-2018-1273 KEV | spring-data-commons: Improper neutralization of special elements allow remote attackers to execute code via crafted requests | CRITICAL | 9.8 | Apr 11, 2018 |
| CVE-2018-1295 | ignite: Possible Execution of Arbitrary Code Within Deserialization Endpoints | CRITICAL | 9.8 | Apr 2, 2018 |
| CVE-2017-7686 | Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixe… | HIGH | 7.5 | Jun 28, 2017 |
| CVE-2016-6805 | Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents. | MEDIUM | 5.9 | Apr 7, 2017 |
Showing 1 to 9 of 9 CVEs