Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2022-36437

Hazelcast: unauthenticated attacker can act with the identity of another authenticated connection

Technology

Hazelcast

CVSS Score

9.1 / 10.0

Affected Versions

Hazelcast 3.12.12 and earlier, 4.0 to 4.0.6, 4.1 to 4.1.9, 4.2 to 4.2.5, 5.0 to 5.0.3, 5.1 to 5.1.2; Hazelcast Jet 4.5.3 and earlier

Upstream Fix

3.12.13, 4.1.10, 4.2.6, 5.0.4, 5.1.3; Jet 4.5.4; no fix for 4.0

Published

December 29, 2022

OSSeva Coverage

Fixed upstream

Description

The connection handler in Hazelcast and Hazelcast Jet lets a remote, unauthenticated attacker access and manipulate data in the cluster with the identity of another connection that has already authenticated. Hazelcast's advisory lists no fixed release for the 4.0 line, so 4.0.6, its last release, remains affected.

Upstream record: NVD · CVE.org

Is your Hazelcast deployment affected?

If you're running Hazelcast 3.12.12 and earlier, 4.0 to 4.0.6, 4.1 to 4.1.9, 4.2 to 4.2.5, 5.0 to 5.0.3, 5.1 to 5.1.2; Hazelcast Jet 4.5.3 and earlier, you need this patch. Book a discovery call to get covered.