CVE-2021-34797

CVE-2021-34797: Apache Geode project log file redaction of sensitive information vulnerability

Vendor Apache Software Foundation
Product Apache Geode
Weakness CWE-532 · Sensitive info in logs
Published January 4, 2022
Last update August 4, 2024

CVSS base score

What the vulnerability does

Description

Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "sysprop-", "javax.net.ssl", or "security-". This issue is fixed by overhauling the log file redaction in Apache Geode versions 1.12.5, 1.13.5, and 1.14.0.

Key dates

Disclosure timeline

January 4, 2022 CVE published
August 4, 2024 Record updated