Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mw25-f5r2-hpc6

Опубликовано: 06 янв. 2022
Источник: github
Github: Прошло ревью

Описание

Insertion of Sensitive Information into Log File in Apache Geode

Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "sysprop-", "javax.net.ssl", or "security-". This issue is fixed by overhauling the log file redaction in Apache Geode versions 1.12.5, 1.13.5, and 1.14.0.

Пакеты

Наименование

org.apache.geode:geode-core

maven
Затронутые версииВерсия исправления

< 1.12.5

1.12.5

Наименование

org.apache.geode:geode-core

maven
Затронутые версииВерсия исправления

>= 1.13.0, < 1.13.5

1.13.5

EPSS

Процентиль: 51%
0.00282
Низкий

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "sysprop-", "javax.net.ssl", or "security-". This issue is fixed by overhauling the log file redaction in Apache Geode versions 1.12.5, 1.13.5, and 1.14.0.

EPSS

Процентиль: 51%
0.00282
Низкий

Дефекты

CWE-532