QID 997544
Date Published: 2024-02-28
QID 997544: Java (Maven) Security Update for com.hazelcast:hazelcast (GHSA-xh6m-7cr7-xx66)
In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions properly, allowing authenticated users to access data stored in the cluster.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-xh6m-7cr7-xx66 for updates and patch information.
Vendor References
- GHSA-xh6m-7cr7-xx66 -
github.com/advisories/GHSA-xh6m-7cr7-xx66
CVEs related to QID 997544
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xh6m-7cr7-xx66 | com.hazelcast:hazelcast |
|