See how hazelcast compares to other vendors in security performance
Impact
A flaw has been found in Hazelcast Enterprise Edition and Community Edition, which would allow a low-privileged malicious client to read arbitrary data in memory from any cluster member (including Java heap memory, off-heap data, and JVM process address space). Additionally, such a client may be able to cause one or more cluster members to crash, or in some Enterprise Edition configurations also corrupt memory contents, potentially leading to remote code execution. Both slim and full distributions are affected.
Patches
Enterprise customers should upgrade to a fixed version of Hazelcast Enterprise Edition: 5.7.0 5.6.1 5.5.10 5.4.5 Customers with extended support contracts should contact Hazelcast Support for information on patches for older versions.
Community Edition users should upgrade to version 5.7.0.
Hazelcast also recommends all customers follow the advice in our Security Hardening guide, including:
Ensure Hazelcast Security is enabled and client authorization is enforced. Define an explicit allowlist for zero config Compact serialization. Avoid deploying clients on internet-facing non-secure networks or non-secure hosts. Ensure your Hazelcast cluster is appropriately protected by firewall rules. Disable any features you are not using.
Workarounds If you cannot update to a fixed version immediately, restrict cluster access to trusted clients only and ensure clients are hardened against compromise.
References
Security Advisory on the Hazelcast Support Portal
Impact
Missing authorization checks in the Predicates API may allow a malicious client to execute arbitrary code on a Hazelcast member.
Patches
Enterprise customers should upgrade to a fixed version of Hazelcast Enterprise Edition: 5.7.0 5.6.1 5.5.10 5.4.5 Customers with extended support contracts should contact Hazelcast Support for information on patches for older versions.
Community Edition users should upgrade to version 5.7.0.
Workarounds None - customers are advised to upgrade to a fixed version as soon as possible.
Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelcast-client XML document (aka a client configuration file), which can be uploaded at the /cluster-connections URI.
Impact In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions properly, allowing authenticated users to access data stored in the cluster.
Patches Fix versions: 5.2.5, 5.3.5, 5.4.0-BETA-1
Workarounds There is no known workaround.
Impact In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which could enable unauthorized clients to access data from files stored on a member's filesystem.
Patches Fix versions: 5.3.5, 5.4.0-BETA-1
Workaround Disabling Hazelcast Jet processing engine in Hazelcast member configuration workarounds the issue. As a result SQL and Jet jobs won't work.
Impact In Hazelcast Platform, 5.0 through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, and Hazelcast IMDG (all versions up to 4.2.z), Executor Services don't check client permissions properly, allowing authenticated users to execute tasks on members without the required permissions granted.
Patches Fix versions: 5.3.0, 5.2.4, 5.1.7, 5.0.5
Workarounds Users are only affected when they already use executor services (i.e., an instance exists as a distributed data structure).
In Hazelcast before 5.3.0, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.
A flaw was found in Hazelcast and Hazelcast Jet. This flaw may allow an attacker unauthenticated access to manipulate data in the cluster.
Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.
The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenarios. As a result, users (clients/members) can be authenticated even if they provide invalid passwords.
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization.
Upstream issue:
https://github.com/hazelcast/hazelcast/issues/8024
Upstream pull:
https://github.com/hazelcast/hazelcast/pull/12230
A flaw was found in the cluster join procedure in Hazelcast. This flaw allows an attacker to gain remote code execution via Java deserialization.