Back to Vulnerability Directory
HIGHFixed upstream

CVE-2023-33265

Hazelcast: executor services do not check client permissions

Technology

Hazelcast

CVSS Score

8.8 / 10.0

Affected Versions

Hazelcast 5.0 to 5.0.4, 5.1 to 5.1.6, 5.2 to 5.2.3

Upstream Fix

5.0.5, 5.1.7, 5.2.4

Published

July 18, 2023

OSSeva Coverage

Fixed upstream

Description

Executor services do not check client permissions properly, so an authenticated client can execute tasks on members without having been granted the permission to do so.

Upstream record: NVD · CVE.org

Is your Hazelcast deployment affected?

If you're running Hazelcast 5.0 to 5.0.4, 5.1 to 5.1.6, 5.2 to 5.2.3, you need this patch. Book a discovery call to get covered.