Описание
In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which could enable unauthorized clients to access data from files stored on a member's filesystem.
A flaw was found in the Hazelcast Platform. The flaw exists in SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which could enable unauthorized clients to access data from files stored on a member's filesystem.
Меры по смягчению последствий
Disabling the Hazelcast Jet processing engine in the Hazelcast member configuration is a workaround for the issue. As a result, SQL and Jet jobs won't work.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel for Spring Boot 3 | Hazelcast | Out of support scope | ||
| Red Hat build of Apache Camel for Spring Boot 4 | Hazelcast | Not affected | ||
| Red Hat Data Grid 8 | Hazelcast | Not affected | ||
| Red Hat Fuse 7 | Hazelcast | Will not fix | ||
| Red Hat Integration Camel K 1 | Hazelcast | Will not fix | ||
| Red Hat JBoss Data Grid 7 | Hazelcast | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 7 | Hazelcast | Will not fix | ||
| Red Hat JBoss Enterprise Application Platform 8 | Hazelcast | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | Hazelcast | Not affected | ||
| streams for Apache Kafka | Hazelcast | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which could enable unauthorized clients to access data from files stored on a member's filesystem.
In Hazelcast Platform through 5.3.4, a security issue exists within th ...
Hazelcast Platform permission checking in CSV File Source connector
Уязвимость платформы анализа данных Hazelcast, связанная с ошибками обработки разрешений, позволяющая нарушителю выполнять произвольные действия
EPSS
6.5 Medium
CVSS3