The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and 5.1.2. The affected Hazelcast Jet versions are through 4.5.3.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-12-29T00:00:00

Updated: 2022-12-29T00:00:00

Reserved: 2022-07-25T00:00:00


Link: CVE-2022-36437

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-12-29T23:15:09.883

Modified: 2023-01-09T18:33:45.887


Link: CVE-2022-36437

JSON object: View

cve-icon Redhat Information

No data.

CWE