Vulnerability GHSA-c5vj-wp4v-mmvx

High Risk
HIGH RISK
CVSS Score: 7.6
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 years ago
July 19, 2023 at 10:08 PM UTC
Hazelcast Executor Services don't check client permissions properly
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.12.0 - 3.12.1
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.12.0 - 3.12.1

Summary

Hazelcast Executor Services don't check client permissions properly

Details

Impact

In Hazelcast Platform, 5.0 through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, and Hazelcast IMDG (all versions up to 4.2.z), Executor Services don't check client permissions properly, allowing authenticated users to execute tasks on members without the required permissions granted.

Patches

Fix versions: 5.3.0, 5.2.4, 5.1.7, 5.0.5

Workarounds

Users are only affected when they already use executor services (i.e., an instance exists as a distributed data structure).

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Critical
9 hours ago
Hazelcast allows arbitrary member memory access by low-privileged client
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-6v25-8wq6-xq4j
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-6v25-8wq6-xq4j
High Risk
9 hours ago
Hazelcast has an authorization bypass in IMap Predicates API
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-w294-6q5q-53p8
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-w294-6q5q-53p8
High Risk
2 years ago
Missing permission checks on Hazelcast client protocol
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 5.3.4 GHSA-xh6m-7cr7-xx66
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 5.3.4 GHSA-xh6m-7cr7-xx66
Medium Risk
2 years ago
Hazelcast Platform permission checking in CSV File Source connector
>=1.5.0 <1.5.4, ==1.6-RC1, ==1.6.0, ==1.7-RC1, ==1.7-RC2, ==1.7-RC3, ==1.7-RC4, ==1.7.0, ==1.7.1, >=1.8.0 <1.8.6, >=1.9.0 <1.9.3, ==1.9.2.1, ==1.9.2.2, ==1.9.2.3, ==1.9.3, ==1.9.3.1, ==1.9.3.2, ==1.9.3.3, ==1.9.3.4, ==1.9.4, ==1.9.4.1, ==1.9.4.2, ==1.9.4.3, ==1.9.4.4, ==1.9.4.5, ==1.9.4.6, ==1.9.4.8, ==2.0-RC1, ==2.0-RC2, >=2.0.0 <2.0.5, >=2.1.0 <2.1.4, ==2.2.0, ==2.3.0, ==2.3.1, ==2.4.0, ==2.4.1, ==2.5.0, ==2.5.1, >=2.6.0 <2.6.11, ==3.0-RC1, ==3.0-RC2, >=3.0.0 <3.0.4, >=3.1.0 <3.1.10, ==3.10-BETA-1, ==3.10-BETA-2, >=3.10.0 <3.10.8, ==3.11-BETA-1, >=3.11.0 <3.11.8, ==3.12-BETA-1, ==3.12-BETA-2, >=3.12.2 <3.12.10, ==3.2-RC1, ==3.2-RC2, >=3.2.0 <3.2.8, ==3.3-EA, ==3.3-EA2, ==3.3-RC1, ==3.3-RC2, ==3.3-RC3, >=3.3.0 <3.3.6, ==3.4-EA, >=3.4.0 <3.4.9, ==3.5-EA, >=3.5.0 <3.5.6, ==3.6-EA, ==3.6-EA2, ==3.6-EA3, ==3.6-RC1, >=3.6.0 <3.6.9, ==3.7-EA, >=3.7.0 <3.7.9, ==3.8-EA, ==3.8-RC1, >=3.8.0 <3.8.10, ==3.9-EA, >=3.9.0 <3.9.5, ==3.12.0, ==3.12.1, >=3.12.10 <3.12.14, ==4.0-BETA-1, ==4.0-BETA-2, >=4.0.0 <4.0.7, ==4.1-BETA-1, >=4.1.0 <4.1.11, ==4.2-BETA-1, >=4.2.0 <4.2.9, ==5.0-BETA-1, ==5.0-BETA-2, >=5.0.0 <5.0.6, ==5.1-BETA-1, >=5.1.0 <5.1.8, >=5.2.0 <5.2.5, >=5.3.0 <5.3.3, ==5.3.4 GHSA-8h4x-xvjp-vf99
>=1.5.0 <1.5.4, ==1.6-RC1, ==1.6.0, ==1.7-RC1, ==1.7-RC2, ==1.7-RC3, ==1.7-RC4, ==1.7.0, ==1.7.1, >=1.8.0 <1.8.6, >=1.9.0 <1.9.3, ==1.9.2.1, ==1.9.2.2, ==1.9.2.3, ==1.9.3, ==1.9.3.1, ==1.9.3.2, ==1.9.3.3, ==1.9.3.4, ==1.9.4, ==1.9.4.1, ==1.9.4.2, ==1.9.4.3, ==1.9.4.4, ==1.9.4.5, ==1.9.4.6, ==1.9.4.8, ==2.0-RC1, ==2.0-RC2, >=2.0.0 <2.0.5, >=2.1.0 <2.1.4, ==2.2.0, ==2.3.0, ==2.3.1, ==2.4.0, ==2.4.1, ==2.5.0, ==2.5.1, >=2.6.0 <2.6.11, ==3.0-RC1, ==3.0-RC2, >=3.0.0 <3.0.4, >=3.1.0 <3.1.10, ==3.10-BETA-1, ==3.10-BETA-2, >=3.10.0 <3.10.8, ==3.11-BETA-1, >=3.11.0 <3.11.8, ==3.12-BETA-1, ==3.12-BETA-2, >=3.12.2 <3.12.10, ==3.2-RC1, ==3.2-RC2, >=3.2.0 <3.2.8, ==3.3-EA, ==3.3-EA2, ==3.3-RC1, ==3.3-RC2, ==3.3-RC3, >=3.3.0 <3.3.6, ==3.4-EA, >=3.4.0 <3.4.9, ==3.5-EA, >=3.5.0 <3.5.6, ==3.6-EA, ==3.6-EA2, ==3.6-EA3, ==3.6-RC1, >=3.6.0 <3.6.9, ==3.7-EA, >=3.7.0 <3.7.9, ==3.8-EA, ==3.8-RC1, >=3.8.0 <3.8.10, ==3.9-EA, >=3.9.0 <3.9.5, ==3.12.0, ==3.12.1, >=3.12.10 <3.12.14, ==4.0-BETA-1, ==4.0-BETA-2, >=4.0.0 <4.0.7, ==4.1-BETA-1, >=4.1.0 <4.1.11, ==4.2-BETA-1, >=4.2.0 <4.2.9, ==5.0-BETA-1, ==5.0-BETA-2, >=5.0.0 <5.0.6, ==5.1-BETA-1, >=5.1.0 <5.1.8, >=5.2.0 <5.2.5, >=5.3.0 <5.3.3, ==5.3.4 GHSA-8h4x-xvjp-vf99
Medium Risk
2 years ago
Hazelcast Platform permission checking in CSV File Source connector
GHSA-8h4x-xvjp-vf99
View all vulnerabilities for these packages

Timeline

Published
3 years ago
July 19, 2023 at 10:08 PM UTC
Fixed (5.2.4)
Unknown
Unknown
Fixed (5.1.7)
Unknown
Unknown
Fixed (5.0.5)
Unknown
Unknown
Last Modified
2 years ago
February 16, 2024 at 08:10 AM UTC