Записи hazelcast
9 опубликованных записей вендора hazelcast.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 77,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-287 Improper Authentication1
- CWE-384 Session Fixation1
- CWE-502 Deserialization of Untrusted Data1
- CWE-522 Insufficiently Protected Credentials1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-862 Missing Authorization1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2022-0265Proof of concept | Improper Restriction of XML External Entity Reference in hazelcast/hazelcasthazelcast · hazelcast · CWE-611 | Критическая9,8 | — | 2,8 % | 3 мар. 2022 г. |
39Наблюдать | CVE-2020-26168Эксплойта нет | The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn'thazelcast · hazelcast · CWE-287 | Критическая9,8 | — | 1,6 % | 9 нояб. 2020 г. |
39Наблюдать | CVE-2024-56518Эксплойта нет | Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelcast-client XML documhazelcast · management center · CWE-94 | Критическая9,8 | — | 1,0 % | 17 апр. 2025 г. |
36Наблюдать | CVE-2022-36437Эксплойта нет | The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster hazelcast · hazelcast · CWE-384 | Критическая9,1 | — | 1,0 % | 29 дек. 2022 г. |
35Наблюдать | CVE-2023-33265Эксплойта нет | In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing auhazelcast · hazelcast · CWE-862 | Высокая8,8 | — | 0,7 % | 18 июл. 2023 г. |
33Наблюдать | CVE-2016-10750Эксплойта нет | In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization.hazelcast · hazelcast · CWE-502 | Высокая8,1 | — | 4,0 % | 22 мая 2019 г. |
30Наблюдать | CVE-2023-45859Эксплойта нет | In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client hazelcast · hazelcast · CWE-922 | Высокая7,6 | — | 0,5 % | 28 февр. 2024 г. |
26Наблюдать | CVE-2023-45860Эксплойта нет | In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector.hazelcast · hazelcast · CWE-89 | Средняя6,5 | — | 0,5 % | 16 февр. 2024 г. |
17Наблюдать | CVE-2023-33264Эксплойта нет | In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuratiohazelcast · hazelcast · CWE-522 | Средняя4,3 | — | 0,7 % | 21 мая 2023 г. |
- CVE-2022-026540В плане
Improper Restriction of XML External Entity Reference in hazelcast/hazelcast
КритическаяCVSS 9,8Proof of conceptEPSS 3 %hazelcast · hazelcast3 мар. 2022 г.
- CVE-2020-2616839Наблюдать
The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %hazelcast · hazelcast9 нояб. 2020 г.
- CVE-2024-5651839Наблюдать
Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelcast-client XML docum
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hazelcast · management center17 апр. 2025 г.
- CVE-2022-3643736Наблюдать
The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %hazelcast · hazelcast29 дек. 2022 г.
- CVE-2023-3326535Наблюдать
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing au
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %hazelcast · hazelcast18 июл. 2023 г.
- CVE-2016-1075033Наблюдать
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization.
ВысокаяCVSS 8,1Эксплойта нетEPSS 4 %hazelcast · hazelcast22 мая 2019 г.
- CVE-2023-4585930Наблюдать
In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client
ВысокаяCVSS 7,6Эксплойта нетEPSS 1 %hazelcast · hazelcast28 февр. 2024 г.
- CVE-2023-4586026Наблюдать
In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %hazelcast · hazelcast16 февр. 2024 г.
- CVE-2023-3326417Наблюдать
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuratio
СредняяCVSS 4,3Эксплойта нетEPSS 1 %hazelcast · hazelcast21 мая 2023 г.