
Cloud Vulnerability DB
A community-led vulnerabilities database
The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, contained a vulnerability where the system didn't properly verify passwords in certain system-user-dn scenarios. This authentication bypass vulnerability was discovered and disclosed in November 2020 (Debian Tracker).
The vulnerability exists in the LDAP authentication implementation where the password verification process was flawed. Specifically, in certain system-user-dn scenarios, the LdapLoginModule failed to properly validate user passwords during the authentication process (Hazelcast Docs).
The vulnerability allowed users (clients/members) to be authenticated even when providing invalid passwords, effectively bypassing the authentication mechanism. This could potentially lead to unauthorized access to the Hazelcast cluster (Debian Tracker).
The vulnerability could be exploited by attempting to authenticate with invalid credentials in specific system-user-dn scenarios, potentially allowing unauthorized access to the system (Debian Tracker).
The vulnerability was addressed in Hazelcast IMDG Enterprise version 4.0.3. Users running affected versions should upgrade to version 4.0.3 or later to resolve this security issue (Hazelcast Docs).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."