Описание
In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions properly, allowing authenticated users to access data stored in the cluster.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| hazelcast | itp | package |
EPSS
Процентиль: 41%
0.00507
Низкий
Связанные уязвимости
CVSS3: 7.6
nvd
больше 2 лет назад
In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions properly, allowing authenticated users to access data stored in the cluster.
CVSS3: 7.6
github
больше 2 лет назад
Missing permission checks on Hazelcast client protocol
EPSS
Процентиль: 41%
0.00507
Низкий