CVE-2023-33264: Infoleak
In Hazelcast before 5.3.0, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.
Other sources
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.hazelcast:hazelcastto a version that resolves this vulnerability.Fixed in 5.3.0 - Upgrade
Upgrade
hazelcastto a version that resolves this vulnerability.Fixed in 5.3.0
Event History
Frequently Asked Questions
What is CVE-2023-33264?
CVE-2023-33264 is a vulnerability in Hazelcast that allows Hazelcast Management Center users to view some of the secrets due to improper masking of passwords in the member configuration.
How severe is CVE-2023-33264?
CVE-2023-33264 has a severity rating of 4.3, which is considered medium.
Which software versions are affected by CVE-2023-33264?
CVE-2023-33264 affects Hazelcast versions 5.0.4 up to and inclusive of 5.2.3.
How can I fix CVE-2023-33264?
To fix CVE-2023-33264, upgrade Hazelcast to version 5.3.0 or later.
Where can I find more information about CVE-2023-33264?
You can find more information about CVE-2023-33264 on the NIST National Vulnerability Database website.