CVE-2022-36437: Critical severity hazelcast vulnerability
A flaw was found in Hazelcast and Hazelcast Jet. This flaw may allow an attacker unauthenticated access to manipulate data in the cluster.
Other sources
The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and 5.1.2. The affected Hazelcast Jet versions are through 4.5.3.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2022-36437?
CVE-2022-36437 is rated as a high severity vulnerability due to the potential for unauthenticated access and data manipulation.
How do I fix CVE-2022-36437?
To fix CVE-2022-36437, upgrade to Hazelcast versions 3.12.13, 4.1.10, 4.2.6, 5.0.4, or 5.1.3.
Which versions of Hazelcast are affected by CVE-2022-36437?
CVE-2022-36437 affects Hazelcast versions prior to 3.12.13, versions between 4.0.0 and 4.1.10, between 4.2.0 and 4.2.6, and between 5.0.0 and 5.0.4.
What type of access does CVE-2022-36437 allow attackers?
CVE-2022-36437 allows unauthenticated remote attackers to access and manipulate data in the Hazelcast cluster.
Is Hazelcast Jet affected by CVE-2022-36437?
Yes, Hazelcast Jet versions prior to 4.5.4 are also affected by CVE-2022-36437.