Impact
Missing authorization checks in the Predicates API may allow a malicious client to execute arbitrary code on a Hazelcast member.
Patches
Enterprise customers should upgrade to a fixed version of Hazelcast Enterprise Edition: 5.7.0 5.6.1 5.5.10 5.4.5 Customers with extended support contracts should contact Hazelcast Support for information on patches for older versions.
Community Edition users should upgrade to version 5.7.0.
Workarounds None - customers are advised to upgrade to a fixed version as soon as possible.
Impact
A flaw has been found in Hazelcast Enterprise Edition and Community Edition, which would allow a low-privileged malicious client to read arbitrary data in memory from any cluster member (including Java heap memory, off-heap data, and JVM process address space). Additionally, such a client may be able to cause one or more cluster members to crash, or in some Enterprise Edition configurations also corrupt memory contents, potentially leading to remote code execution. Both slim and full distributions are affected.
Patches
Enterprise customers should upgrade to a fixed version of Hazelcast Enterprise Edition: 5.7.0 5.6.1 5.5.10 5.4.5 Customers with extended support contracts should contact Hazelcast Support for information on patches for older versions.
Community Edition users should upgrade to version 5.7.0.
Hazelcast also recommends all customers follow the advice in our Security Hardening guide, including:
Ensure Hazelcast Security is enabled and client authorization is enforced. Define an explicit allowlist for zero config Compact serialization. Avoid deploying clients on internet-facing non-secure networks or non-secure hosts. Ensure your Hazelcast cluster is appropriately protected by firewall rules. Disable any features you are not using.
Workarounds If you cannot update to a fixed version immediately, restrict cluster access to trusted clients only and ensure clients are hardened against compromise.
References
Security Advisory on the Hazelcast Support Portal
In Hazelcast before 5.3.0, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.
Impact In Hazelcast Platform, 5.0 through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, and Hazelcast IMDG (all versions up to 4.2.z), Executor Services don't check client permissions properly, allowing authenticated users to execute tasks on members without the required permissions granted.
Patches Fix versions: 5.3.0, 5.2.4, 5.1.7, 5.0.5
Workarounds Users are only affected when they already use executor services (i.e., an instance exists as a distributed data structure).