PT-2025-17196 · Hazelcast · Hazelcast Management Center

Published

2025-04-17

·

Updated

2025-04-17

·

CVE-2024-56518

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hazelcast Management Center versions prior to 6.0
Description The issue allows remote code execution through a JndiLoginModule user.provider.url in a hazelcast-client XML document, which can be uploaded at the "/cluster-connections" API endpoint.
Recommendations For versions prior to 6.0, consider disabling the ability to upload hazelcast-client XML documents at the "/cluster-connections" API endpoint until a patch is available. Restrict access to the JndiLoginModule to minimize the risk of exploitation. Avoid using the user.provider.url variable in the affected API endpoint until the issue is resolved.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-56518

Affected Products

Hazelcast Management Center