Описание
Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "sysprop-", "javax.net.ssl", or "security-". This issue is fixed by overhauling the log file redaction in Apache Geode versions 1.12.5, 1.13.5, and 1.14.0.
Ссылки
- Mailing ListVendor Advisory
- Mailing ListVendor Advisory
- Mailing ListVendor Advisory
- Mailing ListVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.12.4 (включая)Версия от 1.13.0 (включая) до 1.13.4 (включая)
Одно из
cpe:2.3:a:apache:geode:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:geode:*:*:*:*:*:*:*:*
EPSS
Процентиль: 51%
0.00282
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-532
CWE-532
Связанные уязвимости
github
около 4 лет назад
Insertion of Sensitive Information into Log File in Apache Geode
EPSS
Процентиль: 51%
0.00282
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-532
CWE-532