CVE-2021-34797
Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.51%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "sysprop-", "javax.net.ssl", or "security-". This issue is fixed by overhauling the log file redaction in Apache Geode versions 1.12.5, 1.13.5, and 1.14.0.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.51% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-532
- Affected
- apache/geode
- Source
- security@apache.org
References
- https://lists.apache.org/thread/nq2w9gjzm1cjx1rh6zw41ty39qw7qpx4Mailing List, Vendor Advisory
- https://lists.apache.org/thread/p4l0g49rzzzpn8yt9q9p0xp52h3zmsmkMailing List, Vendor Advisory
- https://lists.apache.org/thread/nq2w9gjzm1cjx1rh6zw41ty39qw7qpx4Mailing List, Vendor Advisory
- https://lists.apache.org/thread/p4l0g49rzzzpn8yt9q9p0xp52h3zmsmkMailing List, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.