peter bassill · operator
$ cve CVE-2024-52577 JSON

CVE-2024-52577

9.0
CRITICAL · CVSS 3.1 · EPSS 3.1% (pctl 88)

In your normal cycle

Critical by CVSS (9), but no sign of active exploitation.

Description

In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters are ignored for some Ignite endpoints. The vulnerability could be exploited if an attacker manually crafts an Ignite message containing a vulnerable object whose class is present in the Ignite server classpath and sends it to Ignite server endpoints. Deserialization of such a message by the Ignite server may result in the execution of arbitrary code on the Apache Ignite server side.

Scoring

CVSS9.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS3.13% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2025-02-14
Last modified2026-06-17

Affected (1)

VendorProduct
apacheignite

References

→ the Explorer  ·  watch your stack  ·  NVD