← back
CVE-2021-34797

Apache Geode project log file redaction of sensitive information vulnerability

EPSS 2.9%CWE-532
Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix "sysprop-", "javax.net.ssl", or "security-". This issue is fixed by overhauling the log file redaction in Apache Geode versions 1.12.5, 1.13.5, and 1.14.0.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →