Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Management Center CRITICAL 9.8
CVE-2024-56518

Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelcast-client XML document (aka …

Fix: after 6.0
Fix from $2,300 2025-04-17
Hazelcast HIGH 7.6
CVE-2023-45859

In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operation…

Fix: 5.2.5 / 5.3.5+
Fix from $1,950 2024-02-28
Hazelcast MEDIUM 6.5
CVE-2023-45860

In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequ…

Fix: 5.2.5 / 5.3.5+
Fix from $1,600 2024-02-16
Hazelcast HIGH 8.8
CVE-2023-33265

In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing authenticat…

Fix: 5.0.5 / 5.1.7+
Fix from $1,950 2023-07-18
Hazelcast CRITICAL 9.1
CVE-2022-36437

The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the …

Fix: 3.12.13 / 4.1.10+
Fix from $2,300 2022-12-29
Hazelcast CRITICAL 9.8
CVE-2022-0265

Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.

Patch available
Fix from $2,300 2022-03-03
Hazelcast CRITICAL 9.8
CVE-2020-26168

The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify p…

Fix: 4.0.3+
Fix from $2,300 2020-11-09
Hazelcast HIGH 8.1
CVE-2016-10750

In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a list…

Fix: 3.11+
Fix from $1,950 2019-05-22