
We found results for “”
CVE-2023-45859
Good to know:


Date: February 27, 2024
In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions properly, allowing authenticated users to access data stored in the cluster.
Language: Java
Severity Score
Severity Score
Weakness Type (CWE)
Top Fix

Upgrade Version
Upgrade to version org.apache.cxf.services.sts:cxf-services-sts-war:3.0.5;org.apache.cxf.services.sts:cxf-services-sts-war:3.1.6;org.apache.cxf.services.sts:cxf-services-sts-war:3.0.5;org.apache.cxf.services.sts:cxf-services-sts-war:3.0.5;org.apache.cxf.services.sts:cxf-services-sts-war:3.0.5;org.apache.cxf.services.sts:cxf-services-sts-war:3.0.5;org.apache.cxf.services.sts:cxf-services-sts-war:2.7.1;org.apache.cxf.services.sts:cxf-services-sts-war:3.0.5;org.apache.cxf.services.sts:cxf-services-sts-war:3.0.5;org.apache.cxf.services.sts:cxf-services-sts-war:3.0.3;org.apache.cxf.services.sts:cxf-services-sts-war:2.7.1;com.hazelcast:hazelcast:5.2.5;com.hazelcast:hazelcast:5.2.5;com.hazelcast:hazelcast:5.3.5;com.hazelcast:hazelcast:5.2.5;com.hazelcast:hazelcast:5.2.5
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | LOW |
Availability (A): | LOW |