Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2024-52577
Apache Ignite: class serialization filters ignored on some endpoints, allowing remote code execution
Technology
Apache Ignite
CVSS Score
9.0 / 10.0
Affected Versions
Apache Ignite 2.6.0 before 2.17.0
Upstream Fix
2.17.0
Published
February 14, 2025
OSSeva Coverage
Fixed upstream
Description
Configured class serialization filters are ignored for some Ignite endpoints. An attacker can craft an Ignite message containing a vulnerable object whose class is on the server node's classpath and send it to those endpoints; deserializing it may run arbitrary code on the server. Apache scores it 9.5 under CVSS 4.0.
Is your Apache Ignite deployment affected?
If you're running Apache Ignite 2.6.0 before 2.17.0, you need this patch. Book a discovery call to get covered.