CVE-2023-45860: Hazelcast

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector. This issue arises from inadequate permission checking, which could enable unauthorized clients to access data from files stored on a member's filesystem.

Affected products

  • Hazelcast Hazelcast: up to and including 5.1.7; from 5.2.0, before 5.2.5 (fixed in 5.2.5); from 5.3.0, before 5.3.5 (fixed in 5.3.5)

Published 2024-02-16. Last modified 2026-06-17.