Issue Details
- Vulnerability: Remote Code Execution (RCE)
- Severity: High
- Project: Guiiii-m/apache-nifi
- Branch: master
- Scan Date: Unknown
Issue Description
ignite-core is vulnerable to remote code execution (RCE) attacks. The library does not restrict the types of classes that can be serialized or deserialized, allowing a malicious user to pass a serialized class to the GridClientJdkMarshaller endpoint to inject and execute arbitrary code.
View more details
Remote Code Execution (RCE) in Guiiii-m/apache-nifi (master)
Issue Details
Issue Description
ignite-core is vulnerable to remote code execution (RCE) attacks. The library does not restrict the types of classes that can be serialized or deserialized, allowing a malicious user to pass a serialized class to the
GridClientJdkMarshallerendpoint to inject and execute arbitrary code.View more details