CVE-2023-45860
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
16/02/2024
Last modified:
27/03/2025
Description
In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which could enable unauthorized clients to access data from files stored on a member's filesystem.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:hazelcast:hazelcast:*:*:*:*:*:*:*:* | 5.1.7 (including) | |
cpe:2.3:a:hazelcast:hazelcast:*:*:*:*:*:*:*:* | 5.2.0 (including) | 5.2.5 (excluding) |
cpe:2.3:a:hazelcast:hazelcast:*:*:*:*:*:*:*:* | 5.3.0 (including) | 5.3.5 (excluding) |
To consult the complete list of CPE names with products and versions, see this page