Total vulnerabilities in the database
The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't verify properly the password in some system-user-dn scenarios. As a result, users (clients/members) can be authenticated even if they provide invalid passwords.
Software | From | Fixed in |
---|---|---|
hazelcast / hazelcast | 4.0 | 4.0.3 |
hazelcast / jet | 4.0 | 4.2.x |