StackRadar

CVE-2023-45859

High

Advisory

Published 27 Feb 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.6
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
23
of 17,781 indexed, latest versions
Container images
25
deployed by those charts
Fix available
1 of 2
affected packages

Missing permission checks on Hazelcast client protocol

Carried by container images the latest versions of 23 of 17,781 indexed charts deploy, on 25 images.

Affected packageAffected versionsFixed inImages
hazelcastmaven3.7.5, 3.8.6, 3.10.3, 3.10.4+11 more5.2.5, 5.3.525
hazelcast-allmaven3.7.5, 3.11.2no fix listed2
OSV records
GHSA-xh6m-7cr7-xx66

Charts affected

23 by stars
ChartLatestAffected imagesRadar Score
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
hazelcast@5.2.1
5.2.5

Open the chart page →

6,556
sonarqube-ltssonarqubeVerified publisher1.0.16+981 of 4See more

sonarqube-lts sonarqube 1.0.16+98

1 of the 4 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
library/sonarqube:8.9.2-community88cd63154d4b
hazelcast@4.2
no fix listed

Open the chart page →

4,099
sonarqube-dcesonarqubeVerified publisher0.1.2+1212 of 5See more

sonarqube-dce sonarqube 0.1.2+121

2 of the 5 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
hazelcast@4.2
no fix listed
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
hazelcast@4.2
no fix listed

Open the chart page →

8,698
amorphieamorphie0.1.22 of 18See more

amorphie amorphie 0.1.2

2 of the 18 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.3.18fe26efde8e1
hazelcast@5.3.1
5.3.5
hazelcast/management-center:5.3.2f9d34300d330
hazelcast@5.3.1
5.3.5

Open the chart page →

28,131
hazelcastcloudnativeapp1.3.11 of 1See more

hazelcast cloudnativeapp 1.3.1

1 of the 1 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
hazelcast/hazelcast:3.11.2ca7d5589744f
hazelcast@3.11.2
hazelcast-all@3.11.2
no fix listed
no fix listed

Open the chart page →

4,982
hazelcast-jetcloudnativeapp1.1.01 of 1See more

hazelcast-jet cloudnativeapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
hazelcast/hazelcast-jet:3.0df495e64ea65
hazelcast@3.12
no fix listed

Open the chart page →

5,326
neo4jcloudnativeapp1.0.01 of 1See more

neo4j cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
library/neo4j:3.4.5-enterprisea1ba477fa412
hazelcast@3.7.5
hazelcast-all@3.7.5
no fix listed
no fix listed

Open the chart page →

2,837
orientdbcloudnativeapp0.1.21 of 2See more

orientdb cloudnativeapp 0.1.2

1 of the 2 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
library/orientdb:3.0.1318a6c004398f
hazelcast@3.10.4
no fix listed

Open the chart page →

1,822
hazelcast-jethazelcastVerified publisher1.17.11 of 1See more

hazelcast-jet hazelcast 1.17.1

1 of the 1 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
hazelcast@4.2.4
no fix listed

Open the chart page →

6,102
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
hazelcast@3.10.3
no fix listed

Open the chart page →

12,856
kadeck-webkadeck0.6.01 of 1See more

kadeck-web kadeck 0.6.0

1 of the 1 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
xeotek/kadeck:4.2.94c6b04d9ce55
hazelcast@5.1.3
no fix listed

Open the chart page →

7,254
sonarqubekubesphereVerified publisher6.7.01 of 3See more

sonarqube kubesphere 6.7.0

1 of the 3 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
library/sonarqube:8.9-communityeb2f0be32efd
hazelcast@4.2
no fix listed

Open the chart page →

2,273
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
hazelcast@4.2.4
no fix listed

Open the chart page →

13,607
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
hazelcast@4.2.4
no fix listed

Open the chart page →

11,738
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
hazelcast@4.2.4
no fix listed

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
hazelcast@4.2.4
no fix listed

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
hazelcast@4.2.4
no fix listed

Open the chart page →

13,455
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
hazelcast@4.2.4
no fix listed

Open the chart page →

13,100
sonatype-nexus3simcube1.0.11 of 2See more

sonatype-nexus3 simcube 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
sonatype/nexus3:3.58.1586060431b64
hazelcast@3.12.13
no fix listed

Open the chart page →

4,946
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
hazelcast@3.11.4
no fix listed

Open the chart page →

13,605
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
hazelcast@3.8.6
no fix listed

Open the chart page →

11,841
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
hazelcast@3.12.3
no fix listed

Open the chart page →

5,460
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2023-45859.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
hazelcast@3.12.2.wso2v1
no fix listed

Open the chart page →

6,213

Container images carrying it

25 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
atlassian/confluence-server:7.10.03b9222ab32ef
hazelcast@3.11.4
no fix listed
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
hazelcast@4.2.4
no fix listed
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
hazelcast@4.2.4
no fix listed
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
hazelcast@4.2.4
no fix listed
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
hazelcast@4.2.4
no fix listed
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
hazelcast@4.2.4
no fix listed
1
gurolakman/ussigw-core:1.0.48739565c3ea2
hazelcast@4.2.4
no fix listed
1
hazelcast/hazelcast:5.3.18fe26efde8e1
hazelcast@5.3.1
5.3.5
1
hazelcast/hazelcast:3.11.2ca7d5589744f
hazelcast@3.11.2
hazelcast-all@3.11.2
no fix listed
no fix listed
1
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
hazelcast@4.2.4
no fix listed
1
hazelcast/hazelcast-jet:3.0df495e64ea65
hazelcast@3.12
no fix listed
1
hazelcast/management-center:5.3.2f9d34300d330
hazelcast@5.3.1
5.3.5
1
library/neo4j:3.4.5-enterprisea1ba477fa412
hazelcast@3.7.5
hazelcast-all@3.7.5
no fix listed
no fix listed
1
library/orientdb:3.0.1318a6c004398f
hazelcast@3.10.4
no fix listed
1
library/sonarqube:6.7.6-community0ae5169e3d0f
hazelcast@3.8.6
no fix listed
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
hazelcast@4.2
no fix listed
1
library/sonarqube:8.9.2-community88cd63154d4b
hazelcast@4.2
no fix listed
1
library/sonarqube:8.2-communitya246bc64207e
hazelcast@3.12.3
no fix listed
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
hazelcast@4.2
no fix listed
1
library/sonarqube:8.9-communityeb2f0be32efd
hazelcast@4.2
no fix listed
1
library/sonarqube:10.0.0-communityef9723cf4fe4
hazelcast@5.2.1
5.2.5
1
massimolauri/wso2is:5.11.0-centose08abf0ce767
hazelcast@3.12.2.wso2v1
no fix listed
1
sonatype/nexus3:3.58.1586060431b64
hazelcast@3.12.13
no fix listed
1
xeotek/kadeck:4.2.94c6b04d9ce55
hazelcast@5.1.3
no fix listed
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
hazelcast@3.10.3
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.