Description
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing authenticated users to execute tasks on members without the required permissions granted.
Remediation
References
https://github.com/hazelcast/hazelcast
https://support.hazelcast.com/s/article/Security-Advisory-for-CVE-2023-33265
Related Vulnerabilities
CVE-2019-10318 Vulnerability in maven package org.jenkins-ci.plugins:azure-ad
CVE-2023-49396 Vulnerability in maven package com.jfinal:jfinal
CVE-2020-25802 Vulnerability in maven package org.craftercms:crafter-studio
CVE-2018-1048 Vulnerability in maven package io.undertow:undertow-core
CVE-2020-2184 Vulnerability in maven package org.jenkins-ci.plugins:cvs