Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-36437

Опубликовано: 30 дек. 2022
Источник: redhat
CVSS3: 9.1
EPSS Низкий

Описание

The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and 5.1.2. The affected Hazelcast Jet versions are through 4.5.3.

A flaw was found in Hazelcast and Hazelcast Jet. This flaw may allow an attacker unauthenticated access to manipulate data in the cluster.

Отчет

Red Hat Integration - Camel Quarkus Extensions: Hazelcast is contained in camel-quarkus-hazelcast but it does not affect any supported component. This package is community support only. Hence the low impact for Camel Quarkus Extension.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Integration Camel Quarkus 1hazelcastWill not fix
Red Hat Fuse 7.11.1.P1hazelcastFixedRHSA-2023:048326.01.2023
Red Hat Fuse 7.12FixedRHSA-2023:395429.06.2023
Red Hat Fuse on EAP 7.11.1.P1hazelcastFixedRHSA-2023:066108.02.2023

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-384
https://bugzilla.redhat.com/show_bug.cgi?id=2162053hazelcast: Hazelcast connection caching

EPSS

Процентиль: 58%
0.00362
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
около 3 лет назад

The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and 5.1.2. The affected Hazelcast Jet versions are through 4.5.3.

CVSS3: 9.1
debian
около 3 лет назад

The Connection handler in Hazelcast and Hazelcast Jet allows a remote ...

CVSS3: 9.1
github
около 3 лет назад

Hazelcast connection caching

EPSS

Процентиль: 58%
0.00362
Низкий

9.1 Critical

CVSS3