We found results for “”
CVE-2022-36437
Good to know:
Date: December 29, 2022
The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and 5.1.2. The affected Hazelcast Jet versions are through 4.5.3.
Language: Java
Severity Score
Severity Score
Weakness Type (CWE)
Session Fixation
CWE-384Top Fix
Upgrade Version
Upgrade to version com.hazelcast:hazelcast:3.12.13,4.1.10,4.2.6,5.0.4,5.1.3;com.hazelcast:hazelcast-all:3.12.13,4.1.10,4.2.6;com.hazelcast:hazelcast-jdbc:5.1.1
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | NONE |