REDHAT-BUG-1713215: High severity hazelcast vulnerability
Published May 23, 2019
·Updated
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization.
Upstream issue:
https://github.com/hazelcast/hazelcast/issues/8024
Upstream pull:
https://github.com/hazelcast/hazelcast/pull/12230
Affected Software
1 affected component
hazelcast hazelcast<3.11
Event History
May 23, 2019
Data Sourced
via Red Hat·07:45 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1713215?
REDHAT-BUG-1713215 is categorized as a critical vulnerability due to its potential for remote code execution.
2
How do I fix REDHAT-BUG-1713215?
To remediate REDHAT-BUG-1713215, upgrade Hazelcast to version 3.11 or later.
3
What is the impact of REDHAT-BUG-1713215?
The impact of REDHAT-BUG-1713215 includes the potential for remote attackers to execute arbitrary code on affected systems.
4
Which versions of Hazelcast are affected by REDHAT-BUG-1713215?
Hazelcast versions prior to 3.11 are affected by REDHAT-BUG-1713215.
5
Is there a workaround for REDHAT-BUG-1713215?
No official workaround exists for REDHAT-BUG-1713215; upgrading is the recommended approach.