Skip to content
Noroxi

hazelcast records

9 published records for vendor hazelcast.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
77.8%
Median publish → KEV
No record has entered KEV

All records

9 records
  • Improper Restriction of XML External Entity Reference in hazelcast/hazelcast

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    hazelcast · hazelcastMar 3, 2022

  • The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't

    CriticalCVSS 9.8No exploitEPSS 2%

    hazelcast · hazelcastNov 9, 2020

  • Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelcast-client XML docum

    CriticalCVSS 9.8No exploitEPSS 1%

    hazelcast · management centerApr 17, 2025

  • The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster

    CriticalCVSS 9.1No exploitEPSS 1%

    hazelcast · hazelcastDec 29, 2022

  • In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing au

    HighCVSS 8.8No exploitEPSS 1%

    hazelcast · hazelcastJul 18, 2023

  • In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization.

    HighCVSS 8.1No exploitEPSS 4%

    hazelcast · hazelcastMay 22, 2019

  • In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client

    HighCVSS 7.6No exploitEPSS 1%

    hazelcast · hazelcastFeb 28, 2024

  • In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector.

    MediumCVSS 6.5No exploitEPSS 1%

    hazelcast · hazelcastFeb 16, 2024

  • In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuratio

    MediumCVSS 4.3No exploitEPSS 1%

    hazelcast · hazelcastMay 21, 2023