hazelcast kayıtları
hazelcast üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %77,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-287 Improper Authentication1
- CWE-384 Session Fixation1
- CWE-502 Deserialization of Untrusted Data1
- CWE-522 Insufficiently Protected Credentials1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-862 Missing Authorization1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2022-0265Kavram kanıtı | Improper Restriction of XML External Entity Reference in hazelcast/hazelcasthazelcast · hazelcast · CWE-611 | Kritik9,8 | — | %2,8 | 3 Mar 2022 |
39İzleyin | CVE-2020-26168İstismar yok | The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn'thazelcast · hazelcast · CWE-287 | Kritik9,8 | — | %1,6 | 9 Kas 2020 |
39İzleyin | CVE-2024-56518İstismar yok | Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelcast-client XML documhazelcast · management center · CWE-94 | Kritik9,8 | — | %1,0 | 17 Nis 2025 |
36İzleyin | CVE-2022-36437İstismar yok | The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster hazelcast · hazelcast · CWE-384 | Kritik9,1 | — | %1,0 | 29 Ara 2022 |
35İzleyin | CVE-2023-33265İstismar yok | In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing auhazelcast · hazelcast · CWE-862 | Yüksek8,8 | — | %0,7 | 18 Tem 2023 |
33İzleyin | CVE-2016-10750İstismar yok | In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization.hazelcast · hazelcast · CWE-502 | Yüksek8,1 | — | %4,0 | 22 May 2019 |
30İzleyin | CVE-2023-45859İstismar yok | In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client hazelcast · hazelcast · CWE-922 | Yüksek7,6 | — | %0,5 | 28 Şub 2024 |
26İzleyin | CVE-2023-45860İstismar yok | In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector.hazelcast · hazelcast · CWE-89 | Orta6,5 | — | %0,5 | 16 Şub 2024 |
17İzleyin | CVE-2023-33264İstismar yok | In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuratiohazelcast · hazelcast · CWE-522 | Orta4,3 | — | %0,7 | 21 May 2023 |
- CVE-2022-026540Planlayın
Improper Restriction of XML External Entity Reference in hazelcast/hazelcast
KritikCVSS 9,8Kavram kanıtıEPSS %3hazelcast · hazelcast3 Mar 2022
- CVE-2020-2616839İzleyin
The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't
KritikCVSS 9,8İstismar yokEPSS %2hazelcast · hazelcast9 Kas 2020
- CVE-2024-5651839İzleyin
Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelcast-client XML docum
KritikCVSS 9,8İstismar yokEPSS %1hazelcast · management center17 Nis 2025
- CVE-2022-3643736İzleyin
The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster
KritikCVSS 9,1İstismar yokEPSS %1hazelcast · hazelcast29 Ara 2022
- CVE-2023-3326535İzleyin
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing au
YüksekCVSS 8,8İstismar yokEPSS %1hazelcast · hazelcast18 Tem 2023
- CVE-2016-1075033İzleyin
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization.
YüksekCVSS 8,1İstismar yokEPSS %4hazelcast · hazelcast22 May 2019
- CVE-2023-4585930İzleyin
In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client
YüksekCVSS 7,6İstismar yokEPSS %1hazelcast · hazelcast28 Şub 2024
- CVE-2023-4586026İzleyin
In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector.
OrtaCVSS 6,5İstismar yokEPSS %1hazelcast · hazelcast16 Şub 2024
- CVE-2023-3326417İzleyin
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuratio
OrtaCVSS 4,3İstismar yokEPSS %1hazelcast · hazelcast21 May 2023