CVE-2022-36437
Hazelcast: unauthenticated attacker can act with the identity of another authenticated connection
Technology
Hazelcast
CVSS Score
9.1 / 10.0
Affected Versions
Hazelcast 3.12.12 and earlier, 4.0 to 4.0.6, 4.1 to 4.1.9, 4.2 to 4.2.5, 5.0 to 5.0.3, 5.1 to 5.1.2; Hazelcast Jet 4.5.3 and earlier
Upstream Fix
3.12.13, 4.1.10, 4.2.6, 5.0.4, 5.1.3; Jet 4.5.4; no fix for 4.0
Published
December 29, 2022
OSSeva Coverage
Fixed upstream
Description
The connection handler in Hazelcast and Hazelcast Jet lets a remote, unauthenticated attacker access and manipulate data in the cluster with the identity of another connection that has already authenticated. Hazelcast's advisory lists no fixed release for the 4.0 line, so 4.0.6, its last release, remains affected.
Is your Hazelcast deployment affected?
If you're running Hazelcast 3.12.12 and earlier, 4.0 to 4.0.6, 4.1 to 4.1.9, 4.2 to 4.2.5, 5.0 to 5.0.3, 5.1 to 5.1.2; Hazelcast Jet 4.5.3 and earlier, you need this patch. Book a discovery call to get covered.