Описание
Hazelcast vulnerable to unmasked password exposure
In Hazelcast before 5.3.0, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.
Пакеты
com.hazelcast:hazelcast
>= 4.0-BETA-1, <= 4.2.8
Отсутствует
com.hazelcast:hazelcast
>= 5.0-BETA-1, < 5.0.5
5.0.5
com.hazelcast:hazelcast
>= 5.1-BETA-1, < 5.1.6
5.1.6
com.hazelcast:hazelcast
>= 5.2-BETA-1, < 5.2.4
5.2.4
com.hazelcast:hazelcast
>= 5.3.0-BETA-1, < 5.3.0
5.3.0
Связанные уязвимости
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.
Уязвимость платформы анализа данных Hazelcast, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю раскрыть защищаемую информацию