PT-2023-7546 · Hazelcast · Hazelcast

CVE-2023-33264

·

Publicado

2023-05-21

·

Atualizado

2023-06-02

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Hazelcast versions 5.0.0 through 5.0.4 Hazelcast versions 5.1.0 through 5.1.6 Hazelcast versions 5.2.0 through 5.2.3
Description The issue is related to insufficient protection of registration data in the Hazelcast platform, which can be exploited by a remote attacker to disclose protected information. Specifically, configuration routines do not mask passwords in the member configuration properly, allowing Hazelcast Management Center users to view some secrets.
Recommendations For Hazelcast versions 5.0.0 through 5.0.4, update to a version later than 5.0.4 to fix the issue. For Hazelcast versions 5.1.0 through 5.1.6, update to a version later than 5.1.6 to fix the issue. For Hazelcast versions 5.2.0 through 5.2.3, update to a version later than 5.2.3 to fix the issue. As a temporary workaround, consider restricting access to the Hazelcast Management Center to minimize the risk of exploitation.

Exploit

Correção

Information Disclosure

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08601
CVE-2023-33264
GHSA-5GJ6-62G7-VMGF

Produtos afetados

Hazelcast