PT-2022-23369 · Hazelcast+1 · Hazelcast+3

Degerhz

·

Published

2022-12-27

·

Updated

2023-01-09

·

CVE-2022-36437

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Hazelcast versions prior to 3.12.13 Hazelcast versions prior to 4.1.10 Hazelcast versions prior to 4.2.6 Hazelcast versions prior to 5.1.3 Hazelcast Jet versions prior to 4.5.4
Description The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. If you are using the Apiman Vert.x Gateway prior to Apiman 3.0.0.Final, a connection caching issue in Hazelcast could allow an unauthenticated, remote attacker to access and manipulate data in the cluster with another authenticated connection's identity. The precise risk is difficult to quantify as plugins deployed by users may make use of Hazelcast in a different manner to the main Apiman codebase.
Recommendations Upgrade Hazelcast to version 3.12.13 or later. Upgrade Hazelcast to version 4.1.10 or later. Upgrade Hazelcast to version 4.2.6 or later. Upgrade Hazelcast to version 5.1.3 or later. Upgrade Hazelcast Jet to version 4.5.4 or later. As a temporary workaround, consider enabling TLS and mutual authentication to significantly lower the exploitation risk. If you are using an older version of Apiman and need to remain on that version, contact your Apiman support provider for advice/long-term support.

Fix

Session Fixation

Weakness Enumeration

Related Identifiers

CVE-2022-36437
GHSA-C5HG-MR8R-F6JP
GHSA-Q2FJ-6H62-59M2

Affected Products

Apiman
Apiman Vert.X Gateway
Hazelcast
Hazelcast Jet