CVE-2023-45860

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
16/02/2024
Last modified:
27/03/2025

Description

In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which could enable unauthorized clients to access data from files stored on a member's filesystem.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hazelcast:hazelcast:*:*:*:*:*:*:*:* 5.1.7 (including)
cpe:2.3:a:hazelcast:hazelcast:*:*:*:*:*:*:*:* 5.2.0 (including) 5.2.5 (excluding)
cpe:2.3:a:hazelcast:hazelcast:*:*:*:*:*:*:*:* 5.3.0 (including) 5.3.5 (excluding)