{"id":"GHSA-mw25-f5r2-hpc6","summary":"Insertion of Sensitive Information into Log File in Apache Geode","details":"Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix \"sysprop-\", \"javax.net.ssl\", or \"security-\". This issue is fixed by overhauling the log file redaction in Apache Geode versions 1.12.5, 1.13.5, and 1.14.0.","aliases":["CVE-2021-34797"],"modified":"2024-12-04T05:40:13.857133Z","published":"2022-01-06T22:23:25Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-01-06T19:57:18Z","nvd_published_at":"2022-01-04T09:15:00Z","cwe_ids":["CWE-532"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-34797"},{"type":"PACKAGE","url":"https://github.com/apache/geode"},{"type":"WEB","url":"https://lists.apache.org/thread/nq2w9gjzm1cjx1rh6zw41ty39qw7qpx4"},{"type":"WEB","url":"https://lists.apache.org/thread/p4l0g49rzzzpn8yt9q9p0xp52h3zmsmk"}],"affected":[{"package":{"name":"org.apache.geode:geode-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.geode/geode-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.12.5"}]}],"versions":["1.0.0-incubating","1.0.0-incubating.M2","1.0.0-incubating.M3","1.1.0","1.1.1","1.10.0","1.11.0","1.12.0","1.12.1","1.12.2","1.12.3","1.12.4","1.2.0","1.2.1","1.3.0","1.4.0","1.5.0","1.6.0","1.7.0","1.8.0","1.9.0","1.9.1","1.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-mw25-f5r2-hpc6/GHSA-mw25-f5r2-hpc6.json"}},{"package":{"name":"org.apache.geode:geode-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.geode/geode-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.13.0"},{"fixed":"1.13.5"}]}],"versions":["1.13.0","1.13.1","1.13.2","1.13.3","1.13.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-mw25-f5r2-hpc6/GHSA-mw25-f5r2-hpc6.json"}}],"schema_version":"1.9.0"}