Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:41442
HistoryJul 21, 2023 - 9:47 a.m.

Authorization Bypass

2023-07-2109:47:42
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
hazelcast
authorization bypass
vulnerability
scheduledexecutorservice
permissions

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

38.4%

com.hazelcast:hazelcast is vulnerable to Authorization Bypasses. The vulnerability is due to not enforcing correct permissions when clients invoke the ScheduledExecutorService proxy which allows an authenticated attacker to bypass the authorization mechanisms and execute tasks on members without the required permissions.

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

38.4%

Related for VERACODE:41442