GHSA-w294-6q5q-53p8: Maven/com.hazelcast:hazelcast vulnerability
Impact
Missing authorization checks in the Predicates API may allow a malicious client to execute arbitrary code on a Hazelcast member.
Patches
Enterprise customers should upgrade to a fixed version of Hazelcast Enterprise Edition: 5.7.0 5.6.1 5.5.10 5.4.5 Customers with extended support contracts should contact Hazelcast Support for information on patches for older versions.
Community Edition users should upgrade to version 5.7.0.
Workarounds None - customers are advised to upgrade to a fixed version as soon as possible.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.hazelcast:hazelcastto a version that resolves this vulnerability.Fixed in 5.7.0 - Upgrade
Upgrade
Hazelcastto a version that resolves this vulnerability.Fixed in 5.4.5 - Upgrade
Upgrade
Hazelcastto a version that resolves this vulnerability.Fixed in 5.5.10 - Upgrade
Upgrade
Hazelcastto a version that resolves this vulnerability.Fixed in 5.6.1 - Upgrade
Upgrade
Hazelcastto a version that resolves this vulnerability.Fixed in 5.7.0
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
A malicious client needs to be able to use the Hazelcast Predicates API against a Hazelcast member. The issue is missing authorization checks in that API and can allow arbitrary code execution on the member.
Which fixed releases are available?
Hazelcast Enterprise Edition is fixed in 5.7.0, 5.6.1, 5.5.10, and 5.4.5. Hazelcast Community Edition users should upgrade to 5.7.0; customers on older Enterprise releases with extended support should contact Hazelcast Support.
Is there a workaround if an immediate upgrade is not possible?
No workaround is provided. Customers are advised to upgrade to a fixed version as soon as possible.