PT-2024-4067 · Hazelcast · Hazelcast Platform

Kwart

·

Published

2024-02-16

·

Updated

2025-03-27

·

CVE-2023-45860

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: Hazelcast Platform versions prior to 5.3.5
Description: The issue is related to inadequate permission checking within the SQL mapping for the CSV File Source connector in Hazelcast Platform. This could enable unauthorized clients to access data from files stored on a member's filesystem. The estimated number of potentially affected devices is not provided. There is no information about real-world incidents where this issue was exploited.
Recommendations: For versions prior to 5.3.5, update to version 5.3.5 or later to resolve the issue. As a temporary workaround, consider disabling the Hazelcast Jet processing engine in Hazelcast member configuration to minimize the risk of exploitation, noting that this will prevent SQL and Jet jobs from working.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04514
CVE-2023-45860
GHSA-8H4X-XVJP-VF99

Affected Products

Hazelcast Platform