Apache Ignite Vulnerability Fixes Critical Security Loophole
ID: 7882abd4-a214-5bd8-8222-215fa9e9c509
STIX ID: report--7882abd4-a214-5bd8-8222-215fa9e9c509
Feed Name: securityonline.info
Apache Software Foundation released an advisory for CVE-2025-48977 — an "important" severity path traversal/arbitrary file read vulnerability in Apache Ignite's default web interface affecting versions 2.0.0 through 2.17.0. Attackers can bypass simple path checks using relative path sequences to read files outside the configured home directory, risking exposure of internal data and enabling modification of system libraries or executables that could lead to code execution. Administrators are urged to upgrade to version 2.18 and perform deep code audits and component checks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
