CVE-2021-34797

Severity
7.5HIGH
EPSS
0.4%
top 42.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 4
Latest updateJan 6

Description

Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "sysprop-", "javax.net.ssl", or "security-". This issue is fixed by overhauling the log file redaction in Apache Geode versions 1.12.5, 1.13.5, and 1.14.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Mavenorg.apache.geode:geode-core1.13.01.13.5+1
NVDapache/geode1.13.01.13.4+1
CVEListV5apache_software_foundation/apache_geodeApache Geode1.12.4

🔴Vulnerability Details

3
GHSA
Insertion of Sensitive Information into Log File in Apache Geode2022-01-06
OSV
Insertion of Sensitive Information into Log File in Apache Geode2022-01-06
CVEList
Apache Geode project log file redaction of sensitive information vulnerability2022-01-04
CVE-2021-34797 (HIGH CVSS 7.5) | Apache Geode versions up to 1.12.4 | cvebase.io