Bug 2264532 (CVE-2023-45860) - CVE-2023-45860 Hazelcast: Permission checking in CSV File Source connector
Summary: CVE-2023-45860 Hazelcast: Permission checking in CSV File Source connector
Keywords:
Status: NEW
Alias: CVE-2023-45860
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2264533
TreeView+ depends on / blocked
 
Reported: 2024-02-16 11:33 UTC by Avinash Hanwate
Modified: 2024-04-30 23:00 UTC (History)
36 users (show)

Fixed In Version: com.hazelcast.hazelcast 5.3.4
Doc Type: ---
Doc Text:
A flaw was found in the Hazelcast Platform. The flaw exists in SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which could enable unauthorized clients to access data from files stored on a member's filesystem.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Avinash Hanwate 2024-02-16 11:33:27 UTC
In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which could enable unauthorized clients to access data from files stored on a member's filesystem.

https://github.com/hazelcast/hazelcast/pull/25348
https://github.com/hazelcast/hazelcast/security/advisories/GHSA-8h4x-xvjp-vf99


Note You need to log in before you can comment on or make changes to this bug.