Improper access control in Hazelcast - CVE-2023-45859

 

Improper access control in Hazelcast - CVE-2023-45859

Published: February 27, 2024 / Updated: December 11, 2024


Vulnerability identifier: #VU86859
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-45859
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions for certain client operations. A remote user can bypass implemented security restrictions and gain unauthorized access to the application.


Affected software

Hazelcast
Confluence Data Center
Bitbucket Data Center
Confluence Server
Bitbucket Server

How to mitigate CVE-2023-45859

Install updates from vendor's website.

Hazelcast - addressed in versions 5.2.5, 5.3.5
Confluence Server - addressed in versions 7.19.22, 8.5.9, 8.9.0
Confluence Data Center - addressed in versions 7.19.22, 8.5.9, 8.9.0
Bitbucket Data Center - update to 8.9.14
Bitbucket Server - update to 8.9.14

External References

Related Security Bulletins