Back to Vulnerability Directory
HIGHFixed upstream

CVE-2023-45859

Hazelcast: some client protocol operations skip permission checks

Technology

Hazelcast

CVSS Score

7.6 / 10.0

Affected Versions

Hazelcast through 4.1.10, 4.2 to 4.2.8, 5.0 to 5.0.5, 5.1 to 5.1.7, 5.2.0 to 5.2.4, 5.3.0 to 5.3.4

Upstream Fix

5.2.5, 5.3.5; no fix for 5.1 and earlier

Published

February 28, 2024

OSSeva Coverage

Fixed upstream

Description

Some client operations do not check permissions properly, so authenticated clients can access data stored in the cluster beyond what they are allowed. Hazelcast's advisory lists fixes only for 5.2 and 5.3. The 7.6 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Hazelcast deployment affected?

If you're running Hazelcast through 4.1.10, 4.2 to 4.2.8, 5.0 to 5.0.5, 5.1 to 5.1.7, 5.2.0 to 5.2.4, 5.3.0 to 5.3.4, you need this patch. Book a discovery call to get covered.