CVE-2023-45859

HIGH

Hazelcast <5.3.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions properly, allowing authenticated users to access data stored in the cluster.

Scores

CVSS v3 7.6
EPSS 0.0017
EPSS Percentile 37.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-922
Status published
Products (3)
com.hazelcast/hazelcast 0Maven
com.hazelcast/hazelcast-all 0Maven
hazelcast/hazelcast < 4.1.10
Published Feb 28, 2024
Tracked Since Feb 18, 2026