Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2025-48977

Apache Ignite: REST API cmd=log path traversal reads any file

Technology

Apache Ignite

CVSS Score

6.5 / 10.0

Affected Versions

Apache Ignite 2.0.0 through 2.17.0

Upstream Fix

2.18.0

Published

May 28, 2026

OSSeva Coverage

Fixed upstream

Description

The REST API checked log paths with a simple prefix comparison against the Ignite home directory, which ../ sequences bypass. An authenticated REST API user can read any file on the server with the cmd=log command. Apache scores it 8.5 under CVSS 4.0.

Upstream record: NVD · CVE.org

Is your Apache Ignite deployment affected?

If you're running Apache Ignite 2.0.0 through 2.17.0, you need this patch. Book a discovery call to get covered.