CVE-2020-26168: Critical severity hazelcast vulnerability
The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenarios. As a result, users (clients/members) can be authenticated even if they provide invalid passwords.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26168?
The severity of CVE-2020-26168 is considered high due to the potential for unauthorized access.
How do I fix CVE-2020-26168?
To fix CVE-2020-26168, upgrade Hazelcast IMDG Enterprise to version 4.0.4 or later, or Jet Enterprise to version 4.2 or later.
What systems are affected by CVE-2020-26168?
CVE-2020-26168 affects Hazelcast IMDG Enterprise versions before 4.0.3 and Jet Enterprise versions from 4.0 to 4.2.
Can users authenticate with invalid passwords due to CVE-2020-26168?
Yes, due to CVE-2020-26168, users can be falsely authenticated even if they provide invalid passwords.
What authentication method is vulnerable in CVE-2020-26168?
The LDAP authentication method in Hazelcast is vulnerable in CVE-2020-26168.