Re: [oss-security] [CVE-2014-0114]: Apache Ignite is vulnerable to existing CVE-2014-0114

2018-06-07 Thread Andrey Gura
Hi, I've looked to the problem and didn't see any problem with BeanUtils. Only module that depends on BeanUtils is Cassandra cache store in order to map POJO to CQL queries. Usages are only on Ignite side with configured Cassandra cache store and can't exploit described vulnerability from my

Re: [oss-security] [CVE-2014-0114]: Apache Ignite is vulnerable to existing CVE-2014-0114

2018-06-06 Thread Denis Magda
Hello Tomas, We've just updated the version of Binutils because Ignite doesn't use this library directly. So we don't need to inject addBeanIntrospector call. Binutils are used by some dependencies like Cassandra. Let us confirm that the dependencies shouldn't be upgraded. -- Denis On Wed, Jun