CVE-2023-45859

EUVD-2024-0767
In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions properly, allowing authenticated users to access data stored in the cluster.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.6 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
CISA-ADPADP
7.6 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
Affected Products (NVD)
VendorProductVersion
hazelcasthazelcast
𝑥
≤ 4.1.10
hazelcasthazelcast
4.2.0 ≤
𝑥
≤ 4.2.8
hazelcasthazelcast
5.0.0 ≤
𝑥
≤ 5.0.5
hazelcasthazelcast
5.1.0 ≤
𝑥
≤ 5.1.7
hazelcasthazelcast
5.2.0 ≤
𝑥
< 5.2.5
hazelcasthazelcast
5.3.0 ≤
𝑥
< 5.3.5
𝑥
= Vulnerable software versions