Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2023-45860

Hazelcast: CSV File Source SQL mapping lets clients read member files

Technology

Hazelcast

CVSS Score

6.5 / 10.0

Affected Versions

Hazelcast 5.1.7 and earlier, 5.2.0 to 5.2.4, 5.3.0 to 5.3.4

Upstream Fix

5.2.5, 5.3.5; no fix for 5.1 and earlier

Published

February 16, 2024

OSSeva Coverage

Fixed upstream

Description

Inadequate permission checking in the SQL mapping for the CSV File Source connector could let unauthorized clients read data from files on a member's filesystem.

Upstream record: NVD · CVE.org

Is your Hazelcast deployment affected?

If you're running Hazelcast 5.1.7 and earlier, 5.2.0 to 5.2.4, 5.3.0 to 5.3.4, you need this patch. Book a discovery call to get covered.