CVE-2023-45859

In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions properly, allowing authenticated users to access data stored in the cluster.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.6 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
mitreCNA
---
---
CISA-ADPADP
7.6 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 36%
VendorProductVersion
hazelcasthazelcast
𝑥
≤ 4.1.10
hazelcasthazelcast
4.2.0 ≤
𝑥
≤ 4.2.8
hazelcasthazelcast
5.0.0 ≤
𝑥
≤ 5.0.5
hazelcasthazelcast
5.1.0 ≤
𝑥
≤ 5.1.7
hazelcasthazelcast
5.2.0 ≤
𝑥
< 5.2.5
hazelcasthazelcast
5.3.0 ≤
𝑥
< 5.3.5
𝑥
= Vulnerable software versions