Description
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing authenticated users to execute tasks on members without the required permissions granted.
Remediation
References
https://github.com/hazelcast/hazelcast
https://support.hazelcast.com/s/article/Security-Advisory-for-CVE-2023-33265
Related Vulnerabilities
CVE-2020-2245 Vulnerability in maven package org.jenkins-ci.plugins:valgrind
CVE-2020-6462 Vulnerability in maven package org.webjars.npm:electron
CVE-2021-46440 Vulnerability in npm package strapi
CVE-2020-2301 Vulnerability in maven package org.jenkins-ci.plugins:active-directory
CVE-2023-24446 Vulnerability in maven package org.jenkins-ci.plugins:openid