The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and 5.1.2. The affected Hazelcast Jet versions are through 4.5.3.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-12-29T00:00:00

Updated: 2024-08-03T10:07:33.982Z

Reserved: 2022-07-25T00:00:00

Link: CVE-2022-36437

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-12-29T23:15:09.883

Modified: 2023-01-09T18:33:45.887

Link: CVE-2022-36437

cve-icon Redhat

Severity : Critical

Publid Date: 2022-12-30T00:00:00Z

Links: CVE-2022-36437 - Bugzilla