CVE-2024-56518
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 17, 2025
Updated: Apr 22, 2025
CWE ID 94
Summary
CVE-2024-56518 is a newly discovered vulnerability affecting Hazelcast Management Center versions up to 6.0. This issue allows an attacker to execute arbitrary code remotely by manipulating a JndiLoginModule user.provider.url in a hazelcast-client XML document. The document can be uploaded via the /cluster-connections URI, providing an attack vector for potential threat actors. This vulnerability poses a significant risk and underscores the importance of keeping software up to date to protect against remote code execution attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.