VYPR

Jet

by Hazelcast

CVEs (2)

  • CVE-2020-26168CriNov 9, 2020
    risk 0.64cvss 9.8epss 0.02

    The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenarios. As a result, users (clients/members) can be authenticated even if they…

  • CVE-2022-36437CriDec 29, 2022
    risk 0.59cvss 9.1epss 0.01

    The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and…