Back to Vulnerability Directory
HIGHFixed upstream

CVE-2016-10750

Hazelcast: cluster join request deserialization allows remote code execution

Technology

Hazelcast

CVSS Score

8.1 / 10.0

Affected Versions

Hazelcast before 3.11

Upstream Fix

3.11

Published

May 22, 2019

OSSeva Coverage

Fixed upstream

Description

The cluster join procedure deserializes a JoinRequest from the network. An attacker who can reach a listening member can send a crafted request and run code if vulnerable classes are on the classpath. 3.11 added a java-serialization-filter setting with class blacklisting and whitelisting, which is not enabled by default.

Upstream record: NVD · CVE.org

Is your Hazelcast deployment affected?

If you're running Hazelcast before 3.11, you need this patch. Book a discovery call to get covered.