ZeroHour

CVE-2023-33265

CVSS 3.1
8.8 high
EPSS
<1%p51
Published
()
Modified
Description

In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing authenticated users to execute tasks on members without the required permissions granted.

Vendors
hazelcast
Products
hazelcast, imdg
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.