Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2020-1963
Apache Ignite: H2 SQL functions give access to the filesystem
Technology
Apache Ignite
CVSS Score
9.1 / 10.0
Affected Versions
Apache Ignite 2.8.0 and earlier
Upstream Fix
2.8.1
Published
June 3, 2020
OSSeva Coverage
Fixed upstream
Description
Ignite builds its distributed SQL engine on the H2 database, and H2's built-in SQL functions can be used to read and write the node's filesystem. Where SQL is not used, the advisory's mitigation is to remove ignite-indexing.jar from the classpath; running Ignite as an unprivileged user reduces the risk.
Is your Apache Ignite deployment affected?
If you're running Apache Ignite 2.8.0 and earlier, you need this patch. Book a discovery call to get covered.