In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.
References
Link | Resource |
---|---|
https://github.com/hazelcast/hazelcast/pull/24266 | Patch |
https://github.com/hazelcast/hazelcast/pull/24266 | Patch |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:05
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/hazelcast/hazelcast/pull/24266 - Patch |
26 May 2023, 02:23
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
CWE | CWE-522 | |
First Time |
Hazelcast hazelcast
Hazelcast |
|
CPE | cpe:2.3:a:hazelcast:hazelcast:*:*:*:*:*:*:*:* | |
References | (MISC) https://github.com/hazelcast/hazelcast/pull/24266 - Patch |
22 May 2023, 01:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-05-22 01:15
Updated : 2024-11-21 08:05
NVD link : CVE-2023-33264
Mitre link : CVE-2023-33264
CVE.ORG link : CVE-2023-33264
JSON object : View
Products Affected
hazelcast
- hazelcast
CWE
CWE-522
Insufficiently Protected Credentials