Back

HIGH

hazelcast: java deserialization in join cluster procedure leading to remote code execution

Published May 22, 2019

Description

In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinRequest, and vulnerable classes exist in the classpath, the attacker can run arbitrary code.

Affected products

Remediation

Red Hat statement

The module vertx-hazelcast is not supported in Red Hat OpenShift Application Runtimes (RHOAR) products.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 22, 2019
Updated Aug 6, 2024
Reserved May 22, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Apr 26, 2016
GHSA-JV65-PF7V-F7P8