Remote Code Execution Vulnerability in Hazelcast Management Center
CVE-2024-56518
9.8CRITICAL
What is CVE-2024-56518?
A vulnerability exists in the Hazelcast Management Center that allows attackers to execute arbitrary code remotely. This occurs when a specially crafted JndiLoginModule user.provider.url is included in a hazelcast-client XML document, which is stored improperly in the server. By exploiting this flaw, an attacker can upload a malicious client configuration file via the /cluster-connections endpoint, potentially compromising the system and leading to unauthorized access.
