High severity7.6NVD Advisory· Published Feb 28, 2024· Updated Jun 17, 2026
CVE-2023-45859
CVE-2023-45859
Description
In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check permissions properly, allowing authenticated users to access data stored in the cluster.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.hazelcast:hazelcastMaven | <= 4.1.10 | — |
com.hazelcast:hazelcastMaven | >= 4.2, <= 4.2.8 | — |
com.hazelcast:hazelcastMaven | >= 5.0, <= 5.0.5 | — |
com.hazelcast:hazelcastMaven | >= 5.1, <= 5.1.7 | — |
com.hazelcast:hazelcastMaven | >= 5.2.0, < 5.2.5 | 5.2.5 |
com.hazelcast:hazelcastMaven | >= 5.3.0, < 5.3.5 | 5.3.5 |
com.hazelcast:hazelcast-allMaven | <= 4.1.10 | — |
com.hazelcast:hazelcast-allMaven | >= 4.2, <= 4.2.8 | — |
Affected products
3- ghsa-coords2 versions
<= 4.1.10+ 1 more
- (no CPE)range: <= 4.1.10
- (no CPE)range: <= 4.1.10
Patches
Vulnerability mechanics
References
4- github.com/hazelcast/hazelcast/pull/25509nvdPatchWEB
- github.com/advisories/GHSA-xh6m-7cr7-xx66ghsaADVISORY
- github.com/hazelcast/hazelcast/security/advisories/GHSA-xh6m-7cr7-xx66nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-45859ghsaADVISORY
News mentions
0No linked articles in our index yet.