Medium severity4.3NVD Advisory· Published May 22, 2023· Updated Jun 17, 2026
CVE-2023-33264
CVE-2023-33264
Description
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.hazelcast:hazelcastMaven | >= 4.0-BETA-1, <= 4.2.8 | — |
com.hazelcast:hazelcastMaven | >= 5.0-BETA-1, < 5.0.5 | 5.0.5 |
com.hazelcast:hazelcastMaven | >= 5.1-BETA-1, < 5.1.6 | 5.1.6 |
com.hazelcast:hazelcastMaven | >= 5.2-BETA-1, < 5.2.4 | 5.2.4 |
com.hazelcast:hazelcastMaven | >= 5.3.0-BETA-1, < 5.3.0 | 5.3.0 |
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/hazelcast/hazelcast/pull/24266nvdPatchWEB
- github.com/advisories/GHSA-5gj6-62g7-vmgfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-33264ghsaADVISORY
- github.com/hazelcast/hazelcast/commit/74eed86c2b2b727148c442e98a01d0ca6941a49eghsaWEB
- github.com/hazelcast/hazelcast/pull/24266/commits/80a502d53cc48bf895711ab55f95e3a51e344ac1ghsaWEB
News mentions
0No linked articles in our index yet.