Miggo Logo

CVE-2023-33265: Hazelcast Executor Services don't check client permissions properly

7.6

CVSS Score
3.1

Basic Information

EPSS Score
0.39123%
Published
7/19/2023
Updated
11/7/2023
KEV Status
No
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
com.hazelcast:hazelcastmaven>= 5.2.0, <= 5.2.35.2.4
com.hazelcast:hazelcastmaven>= 5.1.0, <= 5.1.65.1.7
com.hazelcast:hazelcastmaven<= 5.0.45.0.5
com.hazelcast:hazelcast-enterprisemaven>= 5.2.0, <= 5.2.35.2.4
com.hazelcast:hazelcast-enterprisemaven>= 5.1.0, <= 5.1.65.1.7
com.hazelcast:hazelcast-enterprisemaven<= 5.0.45.0.5

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Imp**t In **z*l**st Pl*t*orm, *.* t*rou** *.*.*, *.* t*rou** *.*.*, *n* *.* t*rou** *.*.*, *n* **z*l**st IM** (*ll v*rsions up to *.*.z), *x**utor S*rvi**s *on't ****k *li*nt p*rmissions prop*rly, *llowin* *ut**nti**t** us*rs to *x**ut* t*sks on

Reasoning

No *n*lysis *v*il**l*