Description
Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do that the component communicates to an external PHP server (http://ignite.run) where it needs to send some system properties like Apache Ignite or Java version. Some of the properties might contain user sensitive information.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-0146 | Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do that the component communicates to an external PHP server (http://ignite.run) where it needs to send some system properties like Apache Ignite or Java version. Some of the properties might contain user sensitive information. |
Github GHSA |
GHSA-8p83-68cw-943f | Apache Ignite communicates to an external PHP server where sensitive information is sent |
References
History
No history.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-05T16:12:28.262Z
Reserved: 2017-04-11T00:00:00.000Z
Link: CVE-2017-7686
No data.
Status : Deferred
Published: 2017-06-28T13:29:00.217
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-7686
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA