First published: Thu Dec 29 2022(Updated: )
A flaw was found in Hazelcast and Hazelcast Jet. This flaw may allow an attacker unauthenticated access to manipulate data in the cluster.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/hazelcast | <3.12.13 | 3.12.13 |
redhat/hazelcast | <4.1.10 | 4.1.10 |
redhat/hazelcast | <4.2.6 | 4.2.6 |
redhat/hazelcast | <5.0.4 | 5.0.4 |
redhat/hazelcast | <5.1.3 | 5.1.3 |
Hazelcast | <3.12.13 | |
Hazelcast | <3.12.13 | |
Hazelcast | >=4.0.0<4.1.10 | |
Hazelcast | >=4.0.0<4.1.10 | |
Hazelcast | >=4.2.0<4.2.6 | |
Hazelcast | >=4.2.0<4.2.6 | |
Hazelcast | >=5.0.0<5.0.4 | |
Hazelcast | >=5.0.0<5.0.4 | |
Hazelcast | >=5.1.0<5.1.3 | |
Hazelcast | >=5.1.0<5.1.3 | |
Hazelcast Jet | <4.5.4 | |
Hazelcast Jet | <4.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-36437 is rated as a high severity vulnerability due to the potential for unauthenticated access and data manipulation.
To fix CVE-2022-36437, upgrade to Hazelcast versions 3.12.13, 4.1.10, 4.2.6, 5.0.4, or 5.1.3.
CVE-2022-36437 affects Hazelcast versions prior to 3.12.13, versions between 4.0.0 and 4.1.10, between 4.2.0 and 4.2.6, and between 5.0.0 and 5.0.4.
CVE-2022-36437 allows unauthenticated remote attackers to access and manipulate data in the Hazelcast cluster.
Yes, Hazelcast Jet versions prior to 4.5.4 are also affected by CVE-2022-36437.