Medium severity6.5NVD Advisory· Published Feb 16, 2024· Updated Jun 17, 2026
CVE-2023-45860
CVE-2023-45860
Description
In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which could enable unauthorized clients to access data from files stored on a member's filesystem.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.hazelcast:hazelcastMaven | >= 5.3.0, < 5.3.5 | 5.3.5 |
com.hazelcast:hazelcast-enterpriseMaven | >= 5.3.0, < 5.3.5 | 5.3.5 |
com.hazelcast:hazelcast-enterpriseMaven | >= 5.2.0, < 5.2.5 | 5.2.5 |
com.hazelcast:hazelcast-enterpriseMaven | <= 5.1.7 | — |
com.hazelcast:hazelcastMaven | >= 5.2.0, < 5.2.5 | 5.2.5 |
com.hazelcast:hazelcastMaven | <= 5.1.7 | — |
Affected products
3- Hazelcast/Platformdescription
- ghsa-coords2 versions
>= 5.3.0, < 5.3.5+ 1 more
- (no CPE)range: >= 5.3.0, < 5.3.5
- (no CPE)range: >= 5.3.0, < 5.3.5
Patches
Vulnerability mechanics
References
5- github.com/hazelcast/hazelcast/pull/25348nvdPatchWEB
- github.com/advisories/GHSA-8h4x-xvjp-vf99ghsaADVISORY
- github.com/hazelcast/hazelcast/security/advisories/GHSA-8h4x-xvjp-vf99nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-45860ghsaADVISORY
- github.com/hazelcast/hazelcast/commit/98be233e79cf4bc1ff3c7126a9189988bd0e87bdghsaWEB
News mentions
0No linked articles in our index yet.