24 lines
807 B
JSON
Raw Normal View History

{
"id": "CVE-2023-45859",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-02-28T22:15:26.070",
"lastModified": "2024-02-29T13:49:47.277",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions properly, allowing authenticated users to access data stored in the cluster."
}
],
"metrics": {},
"references": [
{
"url": "https://github.com/hazelcast/hazelcast/pull/25509",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/hazelcast/hazelcast/security/advisories/GHSA-xh6m-7cr7-xx66",
"source": "cve@mitre.org"
}
]
}