icon

We found results for “

CVE-2022-36437

Good to know:

icon
icon

Date: December 29, 2022

The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and 5.1.2. The affected Hazelcast Jet versions are through 4.5.3.

Language: Java

Severity Score

Severity Score

Weakness Type (CWE)

Session Fixation

CWE-384

Top Fix

icon

Upgrade Version

Upgrade to version com.hazelcast:hazelcast:3.12.13,4.1.10,4.2.6,5.0.4,5.1.3;com.hazelcast:hazelcast-all:3.12.13,4.1.10,4.2.6;com.hazelcast:hazelcast-jdbc:5.1.1

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): NONE

Do you need more information?

Contact Us