← Back

CVE-2023-45860

nvd nist
Published: Feb 16, 2024Modified: Mar 27, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which could enable unauthorized clients to access data from files stored on a member's filesystem.

Affected (3)

Products: Hazelcast: Hazelcast
1 product
Hazelcast
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Hazelcast
Up to 5.1.7
From 5.2.0 to 5.2.5
From 5.3.0 to 5.3.5

References (4)

Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.