Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2020-26168
Hazelcast IMDG Enterprise: LDAP login module accepts invalid passwords
Technology
Hazelcast
CVSS Score
9.8 / 10.0
Affected Versions
Hazelcast IMDG Enterprise 4.0 to 4.0.2; Hazelcast Jet Enterprise 4.0 to 4.2
Upstream Fix
IMDG Enterprise 4.0.3; Jet Enterprise 4.3
Published
November 9, 2020
OSSeva Coverage
Fixed upstream
Description
The LdapLoginModule in Hazelcast IMDG Enterprise and Jet Enterprise does not verify the password correctly in some system-user-dn configurations, so clients and members can authenticate with an invalid password. Only clusters that use LDAP authentication are affected.
Is your Hazelcast deployment affected?
If you're running Hazelcast IMDG Enterprise 4.0 to 4.0.2; Hazelcast Jet Enterprise 4.0 to 4.2, you need this patch. Book a discovery call to get covered.