CVE-2023-33265
Hazelcast Executor Services don't check client permissions properly
7.6
HIGH
CVSS 3.1
EPSS 0.57%
描述
### Impact In Hazelcast Platform, 5.0 through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, and Hazelcast IMDG (all versions up to 4.2.z), Executor Services don't check client permissions properly, allowing authenticated users to execute tasks on members without the required permissions granted. ### Patches Fix versions: 5.3.0, 5.2.4, 5.1.7, 5.0.5 ### Workarounds Users are only affected when they already use executor services (i.e., an instance exists as a distributed data structure).
如何修補 CVE-2023-33265
要修補 CVE-2023-33265,請將受影響套件升級到下列已修補版本。
- —升級至 5.2.4 或更新版本
- —升級至 5.2.4 或更新版本
CVE-2023-33265 正在被利用嗎?
低 — EPSS 為 0.6%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- >= 5.2.0, < 5.2.4
- >= 5.2.0, < 5.2.4
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.6 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H |