Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2020-26168

Hazelcast IMDG Enterprise: LDAP login module accepts invalid passwords

Technology

Hazelcast

CVSS Score

9.8 / 10.0

Affected Versions

Hazelcast IMDG Enterprise 4.0 to 4.0.2; Hazelcast Jet Enterprise 4.0 to 4.2

Upstream Fix

IMDG Enterprise 4.0.3; Jet Enterprise 4.3

Published

November 9, 2020

OSSeva Coverage

Fixed upstream

Description

The LdapLoginModule in Hazelcast IMDG Enterprise and Jet Enterprise does not verify the password correctly in some system-user-dn configurations, so clients and members can authenticate with an invalid password. Only clusters that use LDAP authentication are affected.

Upstream record: NVD · CVE.org

Is your Hazelcast deployment affected?

If you're running Hazelcast IMDG Enterprise 4.0 to 4.0.2; Hazelcast Jet Enterprise 4.0 to 4.2, you need this patch. Book a discovery call to get covered.