Description
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users to view some of the secrets.
Remediation
References
https://github.com/hazelcast/hazelcast/pull/24266
Related Vulnerabilities
CVE-2018-19360 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2019-12086 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2015-3253 Vulnerability in maven package org.codehaus.groovy:groovy-all
CVE-2021-27516 Vulnerability in maven package org.webjars.npm:urijs
CVE-2023-27480 Vulnerability in maven package org.xwiki.platform:xwiki-platform-xar-model