QID 997261
Date Published: 2024-02-20
QID 997261: Java (Maven) Security Update for com.hazelcast:hazelcast (GHSA-8h4x-xvjp-vf99)
In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which could enable unauthorized clients to access data from files stored on a member's filesystem.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-8h4x-xvjp-vf99 for updates and patch information.
Vendor References
- GHSA-8h4x-xvjp-vf99 -
github.com/advisories/GHSA-8h4x-xvjp-vf99
CVEs related to QID 997261
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8h4x-xvjp-vf99 | com.hazelcast:hazelcast |
|