CVE Vulnerabilities

CVE-2023-33264

Insufficiently Protected Credentials

Published: May 22, 2023 | Modified: Jun 02, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines dont mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Hazelcast Hazelcast * 5.0.4 (including)
Hazelcast Hazelcast 5.1 (including) 5.1.6 (excluding)
Hazelcast Hazelcast 5.2 (including) 5.2.3 (including)

Potential Mitigations

References