Vulnerability GHSA-8h4x-xvjp-vf99
Medium Risk
MEDIUM RISK
CVSS Score: 6.5
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 years ago
February 16, 2024 at 11:14 PM UTC
Hazelcast Platform permission checking in CSV File Source connector
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.12.0 - 3.12.1 and 5.3.4
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.12.0 - 3.12.1 and 5.3.4
Summary
Hazelcast Platform permission checking in CSV File Source connector
Details
Impact
In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which could enable unauthorized clients to access data from files stored on a member's filesystem.
Patches
Fix versions: 5.3.5, 5.4.0-BETA-1
Workaround
Disabling Hazelcast Jet processing engine in Hazelcast member configuration workarounds the issue. As a result SQL and Jet jobs won't work.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
9 hours ago
Hazelcast allows arbitrary member memory access by low-privileged client
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-6v25-8wq6-xq4j
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-6v25-8wq6-xq4j
High Risk
9 hours ago
Hazelcast has an authorization bypass in IMap Predicates API
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-w294-6q5q-53p8
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-w294-6q5q-53p8
High Risk
2 years ago
Missing permission checks on Hazelcast client protocol
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 5.3.4 GHSA-xh6m-7cr7-xx66
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 5.3.4 GHSA-xh6m-7cr7-xx66
High Risk
3 years ago
Hazelcast Executor Services don't check client permissions properly
>=1.5.0 <1.5.4, ==1.6-RC1, ==1.6.0, ==1.7-RC1, ==1.7-RC2, ==1.7-RC3, ==1.7-RC4, ==1.7.0, ==1.7.1, >=1.8.0 <1.8.6, >=1.9.0 <1.9.3, ==1.9.2.1, ==1.9.2.2, ==1.9.2.3, ==1.9.3, ==1.9.3.1, ==1.9.3.2, ==1.9.3.3, ==1.9.3.4, ==1.9.4, ==1.9.4.1, ==1.9.4.2, ==1.9.4.3, ==1.9.4.4, ==1.9.4.5, ==1.9.4.6, ==1.9.4.8, ==2.0-RC1, ==2.0-RC2, >=2.0.0 <2.0.5, >=2.1.0 <2.1.4, ==2.2.0, ==2.3.0, ==2.3.1, ==2.4.0, ==2.4.1, ==2.5.0, ==2.5.1, >=2.6.0 <2.6.11, ==3.0-RC1, ==3.0-RC2, >=3.0.0 <3.0.4, >=3.1.0 <3.1.10, ==3.10-BETA-1, ==3.10-BETA-2, >=3.10.0 <3.10.8, ==3.11-BETA-1, >=3.11.0 <3.11.8, ==3.12-BETA-1, ==3.12-BETA-2, >=3.12.2 <3.12.10, ==3.2-RC1, ==3.2-RC2, >=3.2.0 <3.2.8, ==3.3-EA, ==3.3-EA2, ==3.3-RC1, ==3.3-RC2, ==3.3-RC3, >=3.3.0 <3.3.6, ==3.4-EA, >=3.4.0 <3.4.9, ==3.5-EA, >=3.5.0 <3.5.6, ==3.6-EA, ==3.6-EA2, ==3.6-EA3, ==3.6-RC1, >=3.6.0 <3.6.9, ==3.7-EA, >=3.7.0 <3.7.9, ==3.8-EA, ==3.8-RC1, >=3.8.0 <3.8.10, ==3.9-EA, >=3.9.0 <3.9.5, ==3.12.0, ==3.12.1, >=3.12.10 <3.12.14, ==4.0-BETA-1, ==4.0-BETA-2, >=4.0.0 <4.0.7, ==4.1-BETA-1, >=4.1.0 <4.1.11, ==4.2-BETA-1, >=4.2.0 <4.2.9, ==5.0-BETA-1, ==5.0-BETA-2, >=5.0.0 <5.0.5, >=5.1.0 <5.1.7, >=5.2.0 <5.2.4 GHSA-c5vj-wp4v-mmvx
>=1.5.0 <1.5.4, ==1.6-RC1, ==1.6.0, ==1.7-RC1, ==1.7-RC2, ==1.7-RC3, ==1.7-RC4, ==1.7.0, ==1.7.1, >=1.8.0 <1.8.6, >=1.9.0 <1.9.3, ==1.9.2.1, ==1.9.2.2, ==1.9.2.3, ==1.9.3, ==1.9.3.1, ==1.9.3.2, ==1.9.3.3, ==1.9.3.4, ==1.9.4, ==1.9.4.1, ==1.9.4.2, ==1.9.4.3, ==1.9.4.4, ==1.9.4.5, ==1.9.4.6, ==1.9.4.8, ==2.0-RC1, ==2.0-RC2, >=2.0.0 <2.0.5, >=2.1.0 <2.1.4, ==2.2.0, ==2.3.0, ==2.3.1, ==2.4.0, ==2.4.1, ==2.5.0, ==2.5.1, >=2.6.0 <2.6.11, ==3.0-RC1, ==3.0-RC2, >=3.0.0 <3.0.4, >=3.1.0 <3.1.10, ==3.10-BETA-1, ==3.10-BETA-2, >=3.10.0 <3.10.8, ==3.11-BETA-1, >=3.11.0 <3.11.8, ==3.12-BETA-1, ==3.12-BETA-2, >=3.12.2 <3.12.10, ==3.2-RC1, ==3.2-RC2, >=3.2.0 <3.2.8, ==3.3-EA, ==3.3-EA2, ==3.3-RC1, ==3.3-RC2, ==3.3-RC3, >=3.3.0 <3.3.6, ==3.4-EA, >=3.4.0 <3.4.9, ==3.5-EA, >=3.5.0 <3.5.6, ==3.6-EA, ==3.6-EA2, ==3.6-EA3, ==3.6-RC1, >=3.6.0 <3.6.9, ==3.7-EA, >=3.7.0 <3.7.9, ==3.8-EA, ==3.8-RC1, >=3.8.0 <3.8.10, ==3.9-EA, >=3.9.0 <3.9.5, ==3.12.0, ==3.12.1, >=3.12.10 <3.12.14, ==4.0-BETA-1, ==4.0-BETA-2, >=4.0.0 <4.0.7, ==4.1-BETA-1, >=4.1.0 <4.1.11, ==4.2-BETA-1, >=4.2.0 <4.2.9, ==5.0-BETA-1, ==5.0-BETA-2, >=5.0.0 <5.0.5, >=5.1.0 <5.1.7, >=5.2.0 <5.2.4 GHSA-c5vj-wp4v-mmvx
High Risk
3 years ago
Hazelcast Executor Services don't check client permissions properly
GHSA-c5vj-wp4v-mmvx
Impacted packages
Timeline
Published
2 years ago
February 16, 2024 at 11:14 PM UTC
Fixed (5.3.5)
Unknown
Unknown
Fixed (5.2.5)
Unknown
Unknown
Last Modified
3 months ago
July 08, 2026 at 06:53 AM UTC