In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.
References
Link | Resource |
---|---|
https://github.com/hazelcast/hazelcast/pull/24266 | Patch |
Configurations
Configuration 1 (hide)
|
History
26 May 2023, 02:23
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://github.com/hazelcast/hazelcast/pull/24266 - Patch | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
CWE | CWE-522 | |
CPE | cpe:2.3:a:hazelcast:hazelcast:*:*:*:*:*:*:*:* |
22 May 2023, 01:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-05-22 01:15
Updated : 2024-02-04 23:37
NVD link : CVE-2023-33264
Mitre link : CVE-2023-33264
CVE.ORG link : CVE-2023-33264
JSON object : View
Products Affected
hazelcast
- hazelcast
CWE
CWE-522
Insufficiently Protected Credentials