In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1474 | In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets. |
Github GHSA |
GHSA-5gj6-62g7-vmgf | Hazelcast vulnerable to unmasked password exposure |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 21 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-21T15:20:07.435Z
Reserved: 2023-05-22T00:00:00
Link: CVE-2023-33264
Updated: 2024-08-02T15:39:36.071Z
Status : Modified
Published: 2023-05-22T01:15:44.333
Modified: 2024-11-21T08:05:17.100
Link: CVE-2023-33264
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA