Back to Vulnerability Directory
HIGHFixed upstream

CVE-2021-34797

Apache Geode: log redaction misses some passwords and security properties

Technology

GemFire / Geode

CVSS Score

7.5 / 10.0

Affected Versions

Apache Geode 1.12.4 and earlier and 1.13.0 to 1.13.4

Upstream Fix

1.12.5, 1.13.5, 1.14.0

Published

January 4, 2022

OSSeva Coverage

Fixed upstream

Description

Values that begin with a character other than a letter or digit are not redacted from log files when they are passwords or security properties with the prefix sysprop-, javax.net.ssl or security-. The fix overhauled log redaction.

Upstream record: NVD · CVE.org

Is your GemFire / Geode deployment affected?

If you're running Apache Geode 1.12.4 and earlier and 1.13.0 to 1.13.4, you need this patch. Book a discovery call to get covered.