CVE-2016-10750
22.05.2019, 14:29
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinRequest, and vulnerable classes exist in the classpath, the attacker can run arbitrary code.Enginsight
Vendor | Product | Version |
---|---|---|
hazelcast | hazelcast | 𝑥 < 3.11 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References