CVE Vulnerabilities

CVE-2023-45859

Insecure Storage of Sensitive Information

Published: Feb 28, 2024 | Modified: Nov 29, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations dont check permissions properly, allowing authenticated users to access data stored in the cluster.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

References