Bug 2210316 (CVE-2023-33264)

Summary: CVE-2023-33264 hazelcast: Improper password mask
Product: [Other] Security Response Reporter: Patrick Del Bello <pdelbell>
Component: vulnerabilityAssignee: Nobody <nobody>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aileenc, chazlett, fmongiar, gmalinko, janstey, jnethert, pdelbell, peholase
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: hazelcast 5.0.4, hazelcast 5.1.6, hazelcast 5.2.3 Doc Type: ---
Doc Text:
A flaw was found in Hazelcast. Configuration routines do not mask the password in the member configuration properly, which may allow Hazelcast Management Center users to view some of the secrets.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2208955    

Description Patrick Del Bello 2023-05-26 14:56:21 UTC
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.

https://github.com/hazelcast/hazelcast/pull/24266