CVE-2022-36437
Summary
| CVE | CVE-2022-36437 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-29 23:15:00 UTC |
| Updated | 2023-01-09 18:33:00 UTC |
| Description | The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and 5.1.2. The affected Hazelcast Jet versions are through 4.5.3. |
Risk And Classification
Problem Types: CWE-384
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hazelcast | Hazelcast | All | All | All | All |
| Application | Hazelcast | Hazelcast | All | All | All | All |
| Application | Hazelcast | Hazelcast-jet | All | All | All | All |
| Application | Hazelcast | Hazelcast-jet | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Hazelcast connection caching · Advisory · hazelcast/hazelcast · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.