CVE-2023-33265: High severity hazelcast hazelcast vulnerability
Impact In Hazelcast Platform, 5.0 through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, and Hazelcast IMDG (all versions up to 4.2.z), Executor Services don't check client permissions properly, allowing authenticated users to execute tasks on members without the required permissions granted.
Patches Fix versions: 5.3.0, 5.2.4, 5.1.7, 5.0.5
Workarounds Users are only affected when they already use executor services (i.e., an instance exists as a distributed data structure).
Other sources
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing authenticated users to execute tasks on members without the required permissions granted.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.hazelcast:hazelcast-enterpriseto a version that resolves this vulnerability.Fixed in 5.0.5 - Upgrade
Upgrade
maven/com.hazelcast:hazelcast-enterpriseto a version that resolves this vulnerability.Fixed in 5.1.7 - Upgrade
Upgrade
maven/com.hazelcast:hazelcast-enterpriseto a version that resolves this vulnerability.Fixed in 5.2.4 - Upgrade
Upgrade
maven/com.hazelcast:hazelcastto a version that resolves this vulnerability.Fixed in 5.0.5 - Upgrade
Upgrade
maven/com.hazelcast:hazelcastto a version that resolves this vulnerability.Fixed in 5.1.7 - Upgrade
Upgrade
maven/com.hazelcast:hazelcastto a version that resolves this vulnerability.Fixed in 5.2.4 - Upgrade
Upgrade
Hazelcast Platformto a version that resolves this vulnerability.Fixed in 5.3.0 - Upgrade
Upgrade
Hazelcast Platformto a version that resolves this vulnerability.Fixed in 5.2.4 - Upgrade
Upgrade
Hazelcast Platformto a version that resolves this vulnerability.Fixed in 5.1.7 - Upgrade
Upgrade
Hazelcast Platformto a version that resolves this vulnerability.Fixed in 5.0.5
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33265?
CVE-2023-33265 has a severity of 8.8 (high).
How does CVE-2023-33265 impact Hazelcast platform?
CVE-2023-33265 allows authenticated users to execute tasks on members without the required permissions granted in Hazelcast Platform versions 5.0 through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3.
Is there a fix available for CVE-2023-33265?
Yes, the remedy for CVE-2023-33265 is to upgrade to version 5.0.5 if using Hazelcast Enterprise, or to upgrade to version 5.0.5 if using Hazelcast IMDG.
Where can I find more information about CVE-2023-33265?
More information about CVE-2023-33265 can be found in the security advisory on the Hazelcast support website and on the GitHub repository for Hazelcast.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-33265?
CVE-2023-33265 is associated with CWE-862.