Hazelcast

    Dashboard / Vendors

    Products: 5
    Vulnerabilities: 9
    Known Exploited: 0
    4
    Critical Level Threats
    3
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-56518

    Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelcast-client XML document (aka a client configuration file), which can be uploaded at the /cluster-connections URI.

    Last Modified: Jul 07, 2025
    Published: Apr 17, 2025

    CVE-2023-45859

    In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions properly, allowing authenticated users to access data stored in the cluster.

    Last Modified: May 13, 2025
    Published: Feb 28, 2024

    CVE-2023-45860

    Hazelcast: Permission checking in CSV File Source connector

    Last Modified: Mar 27, 2025
    Published: Feb 16, 2024

    CVE-2023-33265

    In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing authenticated users to execute tasks on members without the required permissions granted.

    Last Modified: May 02, 2025
    Published: Jul 18, 2023

    CVE-2023-33264

    hazelcast: Improper password mask

    Last Modified: Jan 21, 2025
    Published: May 22, 2023
    Items Per Page