Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-36437

Опубликовано: 29 дек. 2022
Источник: debian
EPSS Низкий

Описание

The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and 5.1.2. The affected Hazelcast Jet versions are through 4.5.3.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
hazelcastitppackage

EPSS

Процентиль: 61%
0.01021
Низкий

Связанные уязвимости

CVSS3: 9.1
redhat
больше 3 лет назад

The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and 5.1.2. The affected Hazelcast Jet versions are through 4.5.3.

CVSS3: 9.1
nvd
больше 3 лет назад

The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and 5.1.2. The affected Hazelcast Jet versions are through 4.5.3.

CVSS3: 9.1
github
больше 3 лет назад

Hazelcast connection caching

EPSS

Процентиль: 61%
0.01021
Низкий