CVE-2017-7686
Apache Ignite communicates to an external PHP server where sensitive information is sent
7.5
HIGH
CVSS 3.1
EPSS 3.0%
描述
Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do that the component communicates to an external PHP server (http://ignite.run) where it needs to send some system properties like Apache Ignite or Java version. Some of the properties might contain user sensitive information.
如何修補 CVE-2017-7686
要修補 CVE-2017-7686,請將受影響套件升級到下列已修補版本。
- —升級至 2.1 或更新版本
CVE-2017-7686 正在被利用嗎?
低 — EPSS 為 3.0%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |