StackRadar

CVE-2023-33264

Medium

Advisory

Published 22 May 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.007
52nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
12
of 17,781 indexed, latest versions
Container images
13
deployed by those charts
Fix available
1 of 1
affected package

Hazelcast vulnerable to unmasked password exposure

Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 13 images.

Affected packageAffected versionsFixed inImages
hazelcastmaven4.2, 4.2.4, 5.1.3, 5.2.15.1.6, 5.2.413
OSV records
GHSA-5gj6-62g7-vmgf

Charts affected

12 by stars
ChartLatestAffected imagesRadar Score
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2023-33264.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
hazelcast@5.2.1
5.2.4

Open the chart page →

6,556
sonarqube-ltssonarqubeVerified publisher1.0.16+981 of 4See more

sonarqube-lts sonarqube 1.0.16+98

1 of the 4 container images this version deploys carry CVE-2023-33264.

Container imageDigestPackageFixed in
library/sonarqube:8.9.2-community88cd63154d4b
hazelcast@4.2
no fix listed

Open the chart page →

4,099
sonarqube-dcesonarqubeVerified publisher0.1.2+1212 of 5See more

sonarqube-dce sonarqube 0.1.2+121

2 of the 5 container images this version deploys carry CVE-2023-33264.

Container imageDigestPackageFixed in
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
hazelcast@4.2
no fix listed
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
hazelcast@4.2
no fix listed

Open the chart page →

8,698
hazelcast-jethazelcastVerified publisher1.17.11 of 1See more

hazelcast-jet hazelcast 1.17.1

1 of the 1 container images this version deploys carry CVE-2023-33264.

Container imageDigestPackageFixed in
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
hazelcast@4.2.4
no fix listed

Open the chart page →

6,102
kadeck-webkadeck0.6.01 of 1See more

kadeck-web kadeck 0.6.0

1 of the 1 container images this version deploys carry CVE-2023-33264.

Container imageDigestPackageFixed in
xeotek/kadeck:4.2.94c6b04d9ce55
hazelcast@5.1.3
5.1.6

Open the chart page →

7,254
sonarqubekubesphereVerified publisher6.7.01 of 3See more

sonarqube kubesphere 6.7.0

1 of the 3 container images this version deploys carry CVE-2023-33264.

Container imageDigestPackageFixed in
library/sonarqube:8.9-communityeb2f0be32efd
hazelcast@4.2
no fix listed

Open the chart page →

2,273
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-33264.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
hazelcast@4.2.4
no fix listed

Open the chart page →

13,607
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-33264.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
hazelcast@4.2.4
no fix listed

Open the chart page →

11,738
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-33264.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
hazelcast@4.2.4
no fix listed

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-33264.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
hazelcast@4.2.4
no fix listed

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-33264.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
hazelcast@4.2.4
no fix listed

Open the chart page →

13,455
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-33264.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
hazelcast@4.2.4
no fix listed

Open the chart page →

13,100

Container images carrying it

13 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gurolakman/smsf-configuration:1.0.49abb3882bcbd
hazelcast@4.2.4
no fix listed
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
hazelcast@4.2.4
no fix listed
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
hazelcast@4.2.4
no fix listed
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
hazelcast@4.2.4
no fix listed
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
hazelcast@4.2.4
no fix listed
1
gurolakman/ussigw-core:1.0.48739565c3ea2
hazelcast@4.2.4
no fix listed
1
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
hazelcast@4.2.4
no fix listed
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
hazelcast@4.2
no fix listed
1
library/sonarqube:8.9.2-community88cd63154d4b
hazelcast@4.2
no fix listed
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
hazelcast@4.2
no fix listed
1
library/sonarqube:8.9-communityeb2f0be32efd
hazelcast@4.2
no fix listed
1
library/sonarqube:10.0.0-communityef9723cf4fe4
hazelcast@5.2.1
5.2.4
1
xeotek/kadeck:4.2.94c6b04d9ce55
hazelcast@5.1.3
5.1.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.