Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7120
HistoryJul 20, 2018 - 10:58 a.m.

Remote Code Execution (RCE)

2018-07-2010:58:25
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

EPSS

0.016

Percentile

87.6%

ignite-core is vulnerable to remote code execution (RCE) attacks. The library does not restrict the types of classes that can be serialized or deserialized, allowing a malicious user to pass a serialized class to the GridClientJdkMarshaller endpoint to inject and execute arbitrary code.

EPSS

0.016

Percentile

87.6%