PT-2025-17196 · Hazelcast · Hazelcast Management Center

CVE-2024-56518

·

Published

2025-04-17

·

Updated

2025-04-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hazelcast Management Center versions prior to 6.0
Description The issue allows remote code execution through a JndiLoginModule user.provider.url in a hazelcast-client XML document, which can be uploaded at the "/cluster-connections" API endpoint.
Recommendations For versions prior to 6.0, consider disabling the ability to upload hazelcast-client XML documents at the "/cluster-connections" API endpoint until a patch is available. Restrict access to the JndiLoginModule to minimize the risk of exploitation. Avoid using the user.provider.url variable in the affected API endpoint until the issue is resolved.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-56518

Affected Products

Hazelcast Management Center