CVE-2023-45859
- EPSS 0.17%
- Veröffentlicht 28.02.2024 22:15:26
- Zuletzt bearbeitet 13.05.2025 14:52:22
In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions properly, allowing authenticated users to access data stored in the cluster...
CVE-2023-45860
- EPSS 0.46%
- Veröffentlicht 16.02.2024 10:15:08
- Zuletzt bearbeitet 27.03.2025 14:24:47
In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which could enable unauthorized clients to access data from files stored on ...
CVE-2023-33265
- EPSS 0.17%
- Veröffentlicht 18.07.2023 16:15:11
- Zuletzt bearbeitet 02.05.2025 10:39:58
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing authenticated users to execute tasks on members without the required permissions granted.
CVE-2023-33264
- EPSS 1.61%
- Veröffentlicht 22.05.2023 01:15:44
- Zuletzt bearbeitet 21.11.2024 08:05:17
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.
CVE-2022-36437
- EPSS 0.37%
- Veröffentlicht 29.12.2022 23:15:09
- Zuletzt bearbeitet 11.04.2025 23:15:26
The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0...
CVE-2022-0265
- EPSS 8.31%
- Veröffentlicht 03.03.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:38:15
Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.
CVE-2020-26168
- EPSS 0.87%
- Veröffentlicht 09.11.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:19:25
The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenarios. As a result, users (clients/members) can be au...
CVE-2016-10750
- EPSS 2.45%
- Veröffentlicht 22.05.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 02:44:39
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinRequest, and vulnerable classes exist in the classpath, t...