CVE-2018-8018
Apache Ignite: GridClientJdkMarshaller deserialization allows code execution
Technology
Apache Ignite
CVSS Score
9.8 / 10.0
Affected Versions
Apache Ignite 2.5 and earlier
Upstream Fix
2.6, with IGNITE_MARSHALLER_WHITELIST or IGNITE_MARSHALLER_BLACKLIST set
Published
July 20, 2018
OSSeva Coverage
Fixed upstream
Description
The serialization mechanism had no list of classes allowed for deserialization, so a specially prepared serialized object sent to the GridClientJdkMarshaller endpoint can run arbitrary code when a vulnerable third-party class is on the classpath. The advisory's mitigation is to upgrade to 2.6 and define allowed classes with the IGNITE_MARSHALLER_WHITELIST or IGNITE_MARSHALLER_BLACKLIST system properties.
Is your Apache Ignite deployment affected?
If you're running Apache Ignite 2.5 and earlier, you need this patch. Book a discovery call to get covered.