PT-2019-7546 · Hazelcast · Hazelcast
Drosenbauer
·
Published
2019-05-22
·
Updated
2022-05-24
·
CVE-2016-10750
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Hazelcast versions prior to 3.11
Description
The cluster join procedure in Hazelcast is susceptible to remote code execution via Java deserialization. An attacker can exploit this by sending a crafted JoinRequest to a listening Hazelcast instance, allowing them to run arbitrary code if vulnerable classes are present in the classpath.
Recommendations
For versions prior to 3.11, update to version 3.11 or later to resolve the issue. As a temporary workaround, consider restricting access to the Hazelcast instance to minimize the risk of exploitation.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hazelcast