9.1

CVE-2022-36437

The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and 5.1.2. The affected Hazelcast Jet versions are through 4.5.3.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HazelcastHazelcast SwEdition- Version < 3.12.13
HazelcastHazelcast SwEditionenterprise Version < 3.12.13
HazelcastHazelcast SwEdition- Version >= 4.0.0 < 4.1.10
HazelcastHazelcast SwEditionenterprise Version >= 4.0.0 < 4.1.10
HazelcastHazelcast SwEdition- Version >= 4.2.0 < 4.2.6
HazelcastHazelcast SwEditionenterprise Version >= 4.2.0 < 4.2.6
HazelcastHazelcast SwEdition- Version >= 5.0.0 < 5.0.4
HazelcastHazelcast SwEditionenterprise Version >= 5.0.0 < 5.0.4
HazelcastHazelcast SwEdition- Version >= 5.1.0 < 5.1.3
HazelcastHazelcast SwEditionenterprise Version >= 5.1.0 < 5.1.3
HazelcastHazelcast-jet SwEdition- Version < 4.5.4
HazelcastHazelcast-jet SwEditionenterprise Version < 4.5.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.585
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-384 Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.