CVE-2023-33265
ADVISORY - githubSummary
Impact
In Hazelcast Platform, 5.0 through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, and Hazelcast IMDG (all versions up to 4.2.z), Executor Services don't check client permissions properly, allowing authenticated users to execute tasks on members without the required permissions granted.
Patches
Fix versions: 5.3.0, 5.2.4, 5.1.7, 5.0.5
Workarounds
Users are only affected when they already use executor services (i.e., an instance exists as a distributed data structure).
EPSS Score: 0.00172 (0.390)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Missing Authorization
ADVISORY - github
Missing Authorization
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in