In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions properly, allowing authenticated users to access data stored in the cluster.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-02-28 22:15
Updated : 2024-11-29 17:15
NVD link : CVE-2023-45859
Mitre link : CVE-2023-45859
CVE.ORG link : CVE-2023-45859
JSON object : View
Products Affected
No product.
CWE
CWE-922
Insecure Storage of Sensitive Information