Back to Vulnerability Directory
HIGHFixed upstream
CVE-2016-10750
Hazelcast: cluster join request deserialization allows remote code execution
Technology
Hazelcast
CVSS Score
8.1 / 10.0
Affected Versions
Hazelcast before 3.11
Upstream Fix
3.11
Published
May 22, 2019
OSSeva Coverage
Fixed upstream
Description
The cluster join procedure deserializes a JoinRequest from the network. An attacker who can reach a listening member can send a crafted request and run code if vulnerable classes are on the classpath. 3.11 added a java-serialization-filter setting with class blacklisting and whitelisting, which is not enabled by default.
Is your Hazelcast deployment affected?
If you're running Hazelcast before 3.11, you need this patch. Book a discovery call to get covered.