GHSA-w294-6q5q-53p8High
Hazelcast has an authorization bypass in IMap Predicates API
🔗 CVE IDs covered (1)
📋 Description
Impact
Missing authorization checks in the Predicates API may allow a malicious client to execute arbitrary code on a Hazelcast member.
Patches
Enterprise customers should upgrade to a fixed version of Hazelcast Enterprise Edition:
- 5.7.0
- 5.6.1
- 5.5.10
- 5.4.5
Customers with extended support contracts should contact Hazelcast Support for information on patches for older versions.
Community Edition users should upgrade to version 5.7.0.
Workarounds
None - customers are advised to upgrade to a fixed version as soon as possible.
🎯 Affected products3
- maven/com.hazelcast:hazelcast:= 5.6.0
- maven/com.hazelcast:hazelcast:>= 5.5.0, < 5.5.10
- maven/com.hazelcast:hazelcast:< 5.4.5
🔗 References (5)
- https://github.com/hazelcast/hazelcast/security/advisories/GHSA-w294-6q5q-53p8
- https://github.com/hazelcast/hazelcast/commit/5d68f4828e2a914398a39f12fe11cafd335cefe0
- https://docs.hazelcast.com/hazelcast/5.7/release-notes/community
- https://docs.hazelcast.com/hazelcast/5.7/release-notes/releases
- https://github.com/advisories/GHSA-w294-6q5q-53p8