{"id":"CVE-2018-1295","details":"In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a specially prepared form of a serialized object to one of the deserialization endpoints of some Ignite components - discovery SPI, Ignite persistence, Memcached endpoint, socket steamer.","aliases":["GHSA-chp4-rv79-68j3"],"modified":"2026-04-10T04:05:07.753131Z","published":"2018-04-02T17:29:00.277Z","references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/45e7d5e2c6face85aab693f5ae0616563132ff757e5a558da80d0209%40%3Cdev.ignite.apache.org%3E"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/103692"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2405"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/ignite","events":[{"introduced":"0"},{"last_affected":"8add7fd5b501b40658096cdde48af9e948aa8150"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"2.3.0"}]}}],"versions":["2.3.0","2.3.0-rc2","release-1.0.0-RC1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1295.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}