Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2020-1963

Apache Ignite: H2 SQL functions give access to the filesystem

Technology

Apache Ignite

CVSS Score

9.1 / 10.0

Affected Versions

Apache Ignite 2.8.0 and earlier

Upstream Fix

2.8.1

Published

June 3, 2020

OSSeva Coverage

Fixed upstream

Description

Ignite builds its distributed SQL engine on the H2 database, and H2's built-in SQL functions can be used to read and write the node's filesystem. Where SQL is not used, the advisory's mitigation is to remove ignite-indexing.jar from the classpath; running Ignite as an unprivileged user reduces the risk.

Upstream record: NVD · CVE.org

Is your Apache Ignite deployment affected?

If you're running Apache Ignite 2.8.0 and earlier, you need this patch. Book a discovery call to get covered.