CVE-2025-48977: Apache Ignite: REST HTTP arbitrary file read vulnerability
Relative Path Traversal vulnerability in Apache Ignite REST API.
Authenticated REST API users can read any file on the server with "cmd=log" command and a log path crafted in a certain way. This issue affects Apache Ignite: from 2.0.0 through 2.17.0.
Users are recommended to upgrade to version 2.18.0, which fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48977?
The severity of CVE-2025-48977 is classified as high with a score of 8.5 according to the CVSS system.
How do I fix CVE-2025-48977?
To fix CVE-2025-48977, users should upgrade to Apache Ignite version 2.18.0 or later.
What type of vulnerability is CVE-2025-48977?
CVE-2025-48977 is a relative path traversal vulnerability affecting the Apache Ignite REST API.
Who is affected by CVE-2025-48977?
Authenticated users of the Apache Ignite REST API from versions 2.0.0 through 2.17.0 are affected by CVE-2025-48977.
What impact can CVE-2025-48977 have on systems?
CVE-2025-48977 allows authenticated users to read any file on the server, potentially exposing sensitive information.