Vulnerability GHSA-xh6m-7cr7-xx66
High Risk
HIGH RISK
CVSS Score: 7.6
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 years ago
February 27, 2024 at 09:54 PM UTC
Missing permission checks on Hazelcast client protocol
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 5.3.4
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 5.3.4
Summary
Missing permission checks on Hazelcast client protocol
Details
Impact
In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions properly, allowing authenticated users to access data stored in the cluster.
Patches
Fix versions: 5.2.5, 5.3.5, 5.4.0-BETA-1
Workarounds
There is no known workaround.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
9 hours ago
Hazelcast allows arbitrary member memory access by low-privileged client
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-6v25-8wq6-xq4j
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-6v25-8wq6-xq4j
High Risk
9 hours ago
Hazelcast has an authorization bypass in IMap Predicates API
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-w294-6q5q-53p8
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.4.8 and 3.9.4 and 3.11.0 - 3.12.1 and 3.12.10 - 3.12.13 and 5.4.0 - 5.6.0 GHSA-w294-6q5q-53p8
Medium Risk
2 years ago
Hazelcast Platform permission checking in CSV File Source connector
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.12.0 - 3.12.1 and 5.3.4 GHSA-8h4x-xvjp-vf99
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.12.0 - 3.12.1 and 5.3.4 GHSA-8h4x-xvjp-vf99
High Risk
3 years ago
Hazelcast Executor Services don't check client permissions properly
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.12.0 - 3.12.1 GHSA-c5vj-wp4v-mmvx
1.6.0 - 1.7.1 and 1.9.3 - 1.9.4 and 2.2.0 - 2.5.1 and 3.12.0 - 3.12.1 GHSA-c5vj-wp4v-mmvx
Medium Risk
3 years ago
Hazelcast vulnerable to unmasked password exposure
5.3.0 GHSA-5gj6-62g7-vmgf
5.3.0 GHSA-5gj6-62g7-vmgf
Impacted packages
Timeline
Published
2 years ago
February 27, 2024 at 09:54 PM UTC
Fixed (5.2.5)
Unknown
Unknown
Fixed (5.3.5)
Unknown
Unknown
Last Modified
3 months ago
July 08, 2026 at 06:53 AM UTC