CVE-2021-34797
Dashboard / Vulnerabilities / CVE-2021-34797
Summary:
Details: Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "sysprop-", "javax.net.ssl", or "security-". This issue is fixed by overhauling the log file redaction in Apache Geode versions 1.12.5, 1.13.5, and 1.14.0.
References: https://lists.apache.org/thread/nq2w9gjzm1cjx1rh6zw41ty39qw7qpx4, https://lists.apache.org/thread/p4l0g49rzzzpn8yt9q9p0xp52h3zmsmk
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 0
Fixed -None
Affected versions
rel/v1.13.4
rel/v1.13.3
rel/v1.13.2
rel/v1.13.1
rel/v1.13.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
