Vulnerability GHSA-8h4x-xvjp-vf99

Medium Risk
MEDIUM RISK
CVSS Score: 6.5
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 years ago
February 16, 2024 at 11:14 PM UTC
Hazelcast Platform permission checking in CSV File Source connector
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.12.0 - 3.12.1 and 5.3.4
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.12.0 - 3.12.1 and 5.3.4

Summary

Hazelcast Platform permission checking in CSV File Source connector

Details

Impact

In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which could enable unauthorized clients to access data from files stored on a member's filesystem.

Patches

Fix versions: 5.3.5, 5.4.0-BETA-1

Workaround

Disabling Hazelcast Jet processing engine in Hazelcast member configuration workarounds the issue. As a result SQL and Jet jobs won't work.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Critical
9 hours ago
Hazelcast allows arbitrary member memory access by low-privileged client
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-6v25-8wq6-xq4j
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-6v25-8wq6-xq4j
High Risk
9 hours ago
Hazelcast has an authorization bypass in IMap Predicates API
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-w294-6q5q-53p8
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-w294-6q5q-53p8
High Risk
2 years ago
Missing permission checks on Hazelcast client protocol
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 5.3.4 GHSA-xh6m-7cr7-xx66
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 5.3.4 GHSA-xh6m-7cr7-xx66
High Risk
3 years ago
Hazelcast Executor Services don't check client permissions properly
>=1.5.0 <1.5.4, ==1.6-RC1, ==1.6.0, ==1.7-RC1, ==1.7-RC2, ==1.7-RC3, ==1.7-RC4, ==1.7.0, ==1.7.1, >=1.8.0 <1.8.6, >=1.9.0 <1.9.3, ==1.9.2.1, ==1.9.2.2, ==1.9.2.3, ==1.9.3, ==1.9.3.1, ==1.9.3.2, ==1.9.3.3, ==1.9.3.4, ==1.9.4, ==1.9.4.1, ==1.9.4.2, ==1.9.4.3, ==1.9.4.4, ==1.9.4.5, ==1.9.4.6, ==1.9.4.8, ==2.0-RC1, ==2.0-RC2, >=2.0.0 <2.0.5, >=2.1.0 <2.1.4, ==2.2.0, ==2.3.0, ==2.3.1, ==2.4.0, ==2.4.1, ==2.5.0, ==2.5.1, >=2.6.0 <2.6.11, ==3.0-RC1, ==3.0-RC2, >=3.0.0 <3.0.4, >=3.1.0 <3.1.10, ==3.10-BETA-1, ==3.10-BETA-2, >=3.10.0 <3.10.8, ==3.11-BETA-1, >=3.11.0 <3.11.8, ==3.12-BETA-1, ==3.12-BETA-2, >=3.12.2 <3.12.10, ==3.2-RC1, ==3.2-RC2, >=3.2.0 <3.2.8, ==3.3-EA, ==3.3-EA2, ==3.3-RC1, ==3.3-RC2, ==3.3-RC3, >=3.3.0 <3.3.6, ==3.4-EA, >=3.4.0 <3.4.9, ==3.5-EA, >=3.5.0 <3.5.6, ==3.6-EA, ==3.6-EA2, ==3.6-EA3, ==3.6-RC1, >=3.6.0 <3.6.9, ==3.7-EA, >=3.7.0 <3.7.9, ==3.8-EA, ==3.8-RC1, >=3.8.0 <3.8.10, ==3.9-EA, >=3.9.0 <3.9.5, ==3.12.0, ==3.12.1, >=3.12.10 <3.12.14, ==4.0-BETA-1, ==4.0-BETA-2, >=4.0.0 <4.0.7, ==4.1-BETA-1, >=4.1.0 <4.1.11, ==4.2-BETA-1, >=4.2.0 <4.2.9, ==5.0-BETA-1, ==5.0-BETA-2, >=5.0.0 <5.0.5, >=5.1.0 <5.1.7, >=5.2.0 <5.2.4 GHSA-c5vj-wp4v-mmvx
>=1.5.0 <1.5.4, ==1.6-RC1, ==1.6.0, ==1.7-RC1, ==1.7-RC2, ==1.7-RC3, ==1.7-RC4, ==1.7.0, ==1.7.1, >=1.8.0 <1.8.6, >=1.9.0 <1.9.3, ==1.9.2.1, ==1.9.2.2, ==1.9.2.3, ==1.9.3, ==1.9.3.1, ==1.9.3.2, ==1.9.3.3, ==1.9.3.4, ==1.9.4, ==1.9.4.1, ==1.9.4.2, ==1.9.4.3, ==1.9.4.4, ==1.9.4.5, ==1.9.4.6, ==1.9.4.8, ==2.0-RC1, ==2.0-RC2, >=2.0.0 <2.0.5, >=2.1.0 <2.1.4, ==2.2.0, ==2.3.0, ==2.3.1, ==2.4.0, ==2.4.1, ==2.5.0, ==2.5.1, >=2.6.0 <2.6.11, ==3.0-RC1, ==3.0-RC2, >=3.0.0 <3.0.4, >=3.1.0 <3.1.10, ==3.10-BETA-1, ==3.10-BETA-2, >=3.10.0 <3.10.8, ==3.11-BETA-1, >=3.11.0 <3.11.8, ==3.12-BETA-1, ==3.12-BETA-2, >=3.12.2 <3.12.10, ==3.2-RC1, ==3.2-RC2, >=3.2.0 <3.2.8, ==3.3-EA, ==3.3-EA2, ==3.3-RC1, ==3.3-RC2, ==3.3-RC3, >=3.3.0 <3.3.6, ==3.4-EA, >=3.4.0 <3.4.9, ==3.5-EA, >=3.5.0 <3.5.6, ==3.6-EA, ==3.6-EA2, ==3.6-EA3, ==3.6-RC1, >=3.6.0 <3.6.9, ==3.7-EA, >=3.7.0 <3.7.9, ==3.8-EA, ==3.8-RC1, >=3.8.0 <3.8.10, ==3.9-EA, >=3.9.0 <3.9.5, ==3.12.0, ==3.12.1, >=3.12.10 <3.12.14, ==4.0-BETA-1, ==4.0-BETA-2, >=4.0.0 <4.0.7, ==4.1-BETA-1, >=4.1.0 <4.1.11, ==4.2-BETA-1, >=4.2.0 <4.2.9, ==5.0-BETA-1, ==5.0-BETA-2, >=5.0.0 <5.0.5, >=5.1.0 <5.1.7, >=5.2.0 <5.2.4 GHSA-c5vj-wp4v-mmvx
High Risk
3 years ago
Hazelcast Executor Services don't check client permissions properly
GHSA-c5vj-wp4v-mmvx
View all vulnerabilities for these packages

Timeline

Published
2 years ago
February 16, 2024 at 11:14 PM UTC
Fixed (5.3.5)
Unknown
Unknown
Fixed (5.2.5)
Unknown
Unknown
Last Modified
3 months ago
July 08, 2026 at 06:53 AM UTC