Skip to content

Conversation

@joshbressers
Copy link

Updates

  • Affected products

Comments
After this was filed, fixes for other branches were merged (look about halfway down in the issue)
hazelcast/hazelcast#24266

Copilot AI review requested due to automatic review settings September 17, 2025 21:31
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates a GitHub security advisory (GHSA-5gj6-62g7-vmgf) for Hazelcast's unmasked password exposure vulnerability to include additional affected product versions and their corresponding fixes.

  • Updates the modification timestamp to reflect recent changes
  • Adds version ranges for Hazelcast 5.0.x, 5.1.x, and 5.2.x branches with their respective fix versions
  • Completes the existing 5.3.0-BETA-1 range that was already present

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

@github-actions github-actions bot changed the base branch from main to joshbressers/advisory-improvement-6147 September 17, 2025 21:32
@helixplant
Copy link

Hi @joshbressers. Before I update the advisory, I want to confirm the following with you to ensure the vulnerable version ranges are correct. I noticed hazelcast/hazelcast#24266 (comment) mentions version 3 not being affected and version 4 being partially affected. Additionally, looking at your proposed changes to this advisory is the following vulnerable version range proposal correct?

Vulnerable from 4.2.0-BETA-1 to 4.2.8, no fix version
Vulnerable from 5.0.0 to 5.0.4, fixed in 5.0.5
Vulnerable from 5.1.0 to 5.1.5, fixed in 5.1.6
Vulnerable from 5.2.0 to 5.2.3, fixed in 5.2.4
Vulnerable in 5.3.0-BETA-1, fixed in 5.3.0

@helixplant
Copy link

Hi @joshbressers. Just checking back in to see if the version range posted above looks correct.

@joshbressers
Copy link
Author

Hi @helixplant

Apologies for missing this

I took a look at versions on Maven Central
https://mvnrepository.com/artifact/com.hazelcast/hazelcast?

Should we start the 5.0 series at 5.0-BETA-1?

Good catch on the 4.x versions. This range is probably acceptable, but we could go all the way back to 4.0-BETA-1

Thanks!

@advisory-database advisory-database bot merged commit e7bc888 into joshbressers/advisory-improvement-6147 Oct 2, 2025
4 checks passed
@advisory-database
Copy link
Contributor

Hi @joshbressers! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the joshbressers-GHSA-5gj6-62g7-vmgf branch October 2, 2025 21:15
@helixplant
Copy link

The advisory should be updated now, please let me know if anything looks off.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants