HIGH 7.6 Maven
Hazelcast Executor Services don't check client permissions properly
GHSA-c5vj-wp4v-mmvx · CVE-2023-33265
Published · Modified
Description
Impact
In Hazelcast Platform, 5.0 through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, and Hazelcast IMDG (all versions up to 4.2.z), Executor Services don't check client permissions properly, allowing authenticated users to execute tasks on members without the required permissions granted.
Patches
Fix versions: 5.3.0, 5.2.4, 5.1.7, 5.0.5
Workarounds
Users are only affected when they already use executor services (i.e., an instance exists as a distributed data structure).
References
- WEB https://github.com/hazelcast/hazelcast/security/advisories/GHSA-c5vj-wp4v-mmvx
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2023-33265
- PACKAGE https://github.com/hazelcast/hazelcast
- WEB https://github.com/hazelcast/hazelcast/releases/tag/v5.0.5
- WEB https://github.com/hazelcast/hazelcast/releases/tag/v5.1.7
- WEB https://github.com/hazelcast/hazelcast/releases/tag/v5.2.4
- WEB https://support.hazelcast.com/s/article/Security-Advisory-for-CVE-2023-33265
Ready to move
Start Securing
Free, no credit card | First findings in minutes