PT-2019-7546 · Hazelcast · Hazelcast

Drosenbauer

·

Published

2019-05-22

·

Updated

2022-05-24

·

CVE-2016-10750

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Hazelcast versions prior to 3.11
Description The cluster join procedure in Hazelcast is susceptible to remote code execution via Java deserialization. An attacker can exploit this by sending a crafted JoinRequest to a listening Hazelcast instance, allowing them to run arbitrary code if vulnerable classes are present in the classpath.
Recommendations For versions prior to 3.11, update to version 3.11 or later to resolve the issue. As a temporary workaround, consider restricting access to the Hazelcast instance to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02985
CVE-2016-10750
GHSA-JV65-PF7V-F7P8

Affected Products

Hazelcast