Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2024-52577

Apache Ignite: class serialization filters ignored on some endpoints, allowing remote code execution

Technology

Apache Ignite

CVSS Score

9.0 / 10.0

Affected Versions

Apache Ignite 2.6.0 before 2.17.0

Upstream Fix

2.17.0

Published

February 14, 2025

OSSeva Coverage

Fixed upstream

Description

Configured class serialization filters are ignored for some Ignite endpoints. An attacker can craft an Ignite message containing a vulnerable object whose class is on the server node's classpath and send it to those endpoints; deserializing it may run arbitrary code on the server. Apache scores it 9.5 under CVSS 4.0.

Upstream record: NVD · CVE.org

Is your Apache Ignite deployment affected?

If you're running Apache Ignite 2.6.0 before 2.17.0, you need this patch. Book a discovery call to get covered.