oss-sec mailing list archives

CVE-2021-34797: Apache Geode project log file redaction of sensitive information vulnerability


From: Kirk Lund <klund () apache org>
Date: Mon, 03 Jan 2022 21:32:36 +0000

Description:

Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when 
using values that begin with characters other than letters or numbers for passwords and security properties with the 
prefix "sysprop-", "javax.net.ssl", or "security-".

This issue is being tracked as GEODE-9354

Credit:

Apache Geode would like to thank Aaron Lindsey for reporting this issue.


Current thread: