
We found results for “”
CVE-2022-36437
Good to know:


Date: December 28, 2022
The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and 5.1.2. The affected Hazelcast Jet versions are through 4.5.3.
Language: Java
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Session Fixation
CWE-384Top Fix

Upgrade Version
Upgrade to version com.hazelcast:hazelcast:4.2.6;com.hazelcast:hazelcast:5.1.3;com.hazelcast:hazelcast:5.0.4;com.hazelcast:hazelcast:3.12.13;com.hazelcast:hazelcast:4.1.10;com.hazelcast.jet:hazelcast-jet:4.5.4
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | NONE |