CVE-2023-45859: High severity hazelcast vulnerability
Impact In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions properly, allowing authenticated users to access data stored in the cluster.
Patches Fix versions: 5.2.5, 5.3.5, 5.4.0-BETA-1
Workarounds There is no known workaround.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-45859?
The severity of CVE-2023-45859 is currently labeled as medium due to improper permission checks allowing authenticated users to access sensitive data.
How do I fix CVE-2023-45859?
To fix CVE-2023-45859, upgrade to Hazelcast versions 5.2.5, 5.3.5, or later.
Which versions of Hazelcast are affected by CVE-2023-45859?
CVE-2023-45859 affects Hazelcast versions 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2.
What types of operations are vulnerable in CVE-2023-45859?
CVE-2023-45859 exposes some client operations that do not properly check permissions, leading to unauthorized access to cluster data.
Is there a workaround for CVE-2023-45859 until I can update?
Currently, there are no documented workarounds for CVE-2023-45859, so upgrading to a fixed version is the best course of action.