Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-36437

Опубликовано: 30 дек. 2022
Источник: redhat
CVSS3: 9.1

Описание

The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and 5.1.2. The affected Hazelcast Jet versions are through 4.5.3.

A flaw was found in Hazelcast and Hazelcast Jet. This flaw may allow an attacker unauthenticated access to manipulate data in the cluster.

Отчет

Red Hat Integration - Camel Quarkus Extensions: Hazelcast is contained in camel-quarkus-hazelcast but it does not affect any supported component. This package is community support only. Hence the low impact for Camel Quarkus Extension.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Integration Camel Quarkus 1hazelcastWill not fix
Red Hat Fuse 7.11.1.P1hazelcastFixedRHSA-2023:048326.01.2023
Red Hat Fuse 7.12FixedRHSA-2023:395429.06.2023
Red Hat Fuse on EAP 7.11.1.P1hazelcastFixedRHSA-2023:066108.02.2023

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-384
https://bugzilla.redhat.com/show_bug.cgi?id=2162053hazelcast: Hazelcast connection caching

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
больше 3 лет назад

The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and 5.1.2. The affected Hazelcast Jet versions are through 4.5.3.

CVSS3: 9.1
debian
больше 3 лет назад

The Connection handler in Hazelcast and Hazelcast Jet allows a remote ...

CVSS3: 9.1
github
больше 3 лет назад

Hazelcast connection caching

9.1 Critical

CVSS3