PT-2022-23369 · Hazelcast+1 · Hazelcast+3
Degerhz
·
Published
2022-12-27
·
Updated
2023-01-09
·
CVE-2022-36437
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Hazelcast versions prior to 3.12.13
Hazelcast versions prior to 4.1.10
Hazelcast versions prior to 4.2.6
Hazelcast versions prior to 5.1.3
Hazelcast Jet versions prior to 4.5.4
Description
The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. If you are using the Apiman Vert.x Gateway prior to Apiman 3.0.0.Final, a connection caching issue in Hazelcast could allow an unauthenticated, remote attacker to access and manipulate data in the cluster with another authenticated connection's identity. The precise risk is difficult to quantify as plugins deployed by users may make use of Hazelcast in a different manner to the main Apiman codebase.
Recommendations
Upgrade Hazelcast to version 3.12.13 or later.
Upgrade Hazelcast to version 4.1.10 or later.
Upgrade Hazelcast to version 4.2.6 or later.
Upgrade Hazelcast to version 5.1.3 or later.
Upgrade Hazelcast Jet to version 4.5.4 or later.
As a temporary workaround, consider enabling TLS and mutual authentication to significantly lower the exploitation risk. If you are using an older version of Apiman and need to remain on that version, contact your Apiman support provider for advice/long-term support.
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apiman
Apiman Vert.X Gateway
Hazelcast
Hazelcast Jet