Vulnerability GHSA-c5vj-wp4v-mmvx
High Risk
HIGH RISK
CVSS Score: 7.6
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 years ago
July 19, 2023 at 10:08 PM UTC
Hazelcast Executor Services don't check client permissions properly
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.12.0 - 3.12.1
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.12.0 - 3.12.1
Summary
Hazelcast Executor Services don't check client permissions properly
Details
Impact
In Hazelcast Platform, 5.0 through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, and Hazelcast IMDG (all versions up to 4.2.z), Executor Services don't check client permissions properly, allowing authenticated users to execute tasks on members without the required permissions granted.
Patches
Fix versions: 5.3.0, 5.2.4, 5.1.7, 5.0.5
Workarounds
Users are only affected when they already use executor services (i.e., an instance exists as a distributed data structure).
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
9 hours ago
Hazelcast allows arbitrary member memory access by low-privileged client
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-6v25-8wq6-xq4j
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-6v25-8wq6-xq4j
High Risk
9 hours ago
Hazelcast has an authorization bypass in IMap Predicates API
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-w294-6q5q-53p8
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-w294-6q5q-53p8
High Risk
2 years ago
Missing permission checks on Hazelcast client protocol
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 5.3.4 GHSA-xh6m-7cr7-xx66
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 5.3.4 GHSA-xh6m-7cr7-xx66
Medium Risk
2 years ago
Hazelcast Platform permission checking in CSV File Source connector
>=1.5.0 <1.5.4, ==1.6-RC1, ==1.6.0, ==1.7-RC1, ==1.7-RC2, ==1.7-RC3, ==1.7-RC4, ==1.7.0, ==1.7.1, >=1.8.0 <1.8.6, >=1.9.0 <1.9.3, ==1.9.2.1, ==1.9.2.2, ==1.9.2.3, ==1.9.3, ==1.9.3.1, ==1.9.3.2, ==1.9.3.3, ==1.9.3.4, ==1.9.4, ==1.9.4.1, ==1.9.4.2, ==1.9.4.3, ==1.9.4.4, ==1.9.4.5, ==1.9.4.6, ==1.9.4.8, ==2.0-RC1, ==2.0-RC2, >=2.0.0 <2.0.5, >=2.1.0 <2.1.4, ==2.2.0, ==2.3.0, ==2.3.1, ==2.4.0, ==2.4.1, ==2.5.0, ==2.5.1, >=2.6.0 <2.6.11, ==3.0-RC1, ==3.0-RC2, >=3.0.0 <3.0.4, >=3.1.0 <3.1.10, ==3.10-BETA-1, ==3.10-BETA-2, >=3.10.0 <3.10.8, ==3.11-BETA-1, >=3.11.0 <3.11.8, ==3.12-BETA-1, ==3.12-BETA-2, >=3.12.2 <3.12.10, ==3.2-RC1, ==3.2-RC2, >=3.2.0 <3.2.8, ==3.3-EA, ==3.3-EA2, ==3.3-RC1, ==3.3-RC2, ==3.3-RC3, >=3.3.0 <3.3.6, ==3.4-EA, >=3.4.0 <3.4.9, ==3.5-EA, >=3.5.0 <3.5.6, ==3.6-EA, ==3.6-EA2, ==3.6-EA3, ==3.6-RC1, >=3.6.0 <3.6.9, ==3.7-EA, >=3.7.0 <3.7.9, ==3.8-EA, ==3.8-RC1, >=3.8.0 <3.8.10, ==3.9-EA, >=3.9.0 <3.9.5, ==3.12.0, ==3.12.1, >=3.12.10 <3.12.14, ==4.0-BETA-1, ==4.0-BETA-2, >=4.0.0 <4.0.7, ==4.1-BETA-1, >=4.1.0 <4.1.11, ==4.2-BETA-1, >=4.2.0 <4.2.9, ==5.0-BETA-1, ==5.0-BETA-2, >=5.0.0 <5.0.6, ==5.1-BETA-1, >=5.1.0 <5.1.8, >=5.2.0 <5.2.5, >=5.3.0 <5.3.3, ==5.3.4 GHSA-8h4x-xvjp-vf99
>=1.5.0 <1.5.4, ==1.6-RC1, ==1.6.0, ==1.7-RC1, ==1.7-RC2, ==1.7-RC3, ==1.7-RC4, ==1.7.0, ==1.7.1, >=1.8.0 <1.8.6, >=1.9.0 <1.9.3, ==1.9.2.1, ==1.9.2.2, ==1.9.2.3, ==1.9.3, ==1.9.3.1, ==1.9.3.2, ==1.9.3.3, ==1.9.3.4, ==1.9.4, ==1.9.4.1, ==1.9.4.2, ==1.9.4.3, ==1.9.4.4, ==1.9.4.5, ==1.9.4.6, ==1.9.4.8, ==2.0-RC1, ==2.0-RC2, >=2.0.0 <2.0.5, >=2.1.0 <2.1.4, ==2.2.0, ==2.3.0, ==2.3.1, ==2.4.0, ==2.4.1, ==2.5.0, ==2.5.1, >=2.6.0 <2.6.11, ==3.0-RC1, ==3.0-RC2, >=3.0.0 <3.0.4, >=3.1.0 <3.1.10, ==3.10-BETA-1, ==3.10-BETA-2, >=3.10.0 <3.10.8, ==3.11-BETA-1, >=3.11.0 <3.11.8, ==3.12-BETA-1, ==3.12-BETA-2, >=3.12.2 <3.12.10, ==3.2-RC1, ==3.2-RC2, >=3.2.0 <3.2.8, ==3.3-EA, ==3.3-EA2, ==3.3-RC1, ==3.3-RC2, ==3.3-RC3, >=3.3.0 <3.3.6, ==3.4-EA, >=3.4.0 <3.4.9, ==3.5-EA, >=3.5.0 <3.5.6, ==3.6-EA, ==3.6-EA2, ==3.6-EA3, ==3.6-RC1, >=3.6.0 <3.6.9, ==3.7-EA, >=3.7.0 <3.7.9, ==3.8-EA, ==3.8-RC1, >=3.8.0 <3.8.10, ==3.9-EA, >=3.9.0 <3.9.5, ==3.12.0, ==3.12.1, >=3.12.10 <3.12.14, ==4.0-BETA-1, ==4.0-BETA-2, >=4.0.0 <4.0.7, ==4.1-BETA-1, >=4.1.0 <4.1.11, ==4.2-BETA-1, >=4.2.0 <4.2.9, ==5.0-BETA-1, ==5.0-BETA-2, >=5.0.0 <5.0.6, ==5.1-BETA-1, >=5.1.0 <5.1.8, >=5.2.0 <5.2.5, >=5.3.0 <5.3.3, ==5.3.4 GHSA-8h4x-xvjp-vf99
Medium Risk
2 years ago
Hazelcast Platform permission checking in CSV File Source connector
GHSA-8h4x-xvjp-vf99
Impacted packages
Timeline
Published
3 years ago
July 19, 2023 at 10:08 PM UTC
Fixed (5.2.4)
Unknown
Unknown
Fixed (5.1.7)
Unknown
Unknown
Fixed (5.0.5)
Unknown
Unknown
Last Modified
2 years ago
February 16, 2024 at 08:10 AM UTC