{"id":"CVE-2021-34797","aliases":["GHSA-mw25-f5r2-hpc6"],"url":"https://o3.security/vulnerability/CVE-2021-34797","summary":"Insertion of Sensitive Information into Log File in Apache Geode","details":"Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with characters other than letters or numbers for passwords and security properties with the prefix \"sysprop-\", \"javax.net.ssl\", or \"security-\". This issue is fixed by overhauling the log file redaction in Apache Geode versions 1.12.5, 1.13.5, and 1.14.0.","published":"2022-01-04T09:15:07.127Z","modified":"2026-07-08T21:27:28.873748Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.geode:geode-core","fixedVersion":"1.12.5"},{"ecosystem":"Maven","name":"org.apache.geode:geode-core","fixedVersion":"1.13.5"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://lists.apache.org/thread/nq2w9gjzm1cjx1rh6zw41ty39qw7qpx4"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/p4l0g49rzzzpn8yt9q9p0xp52h3zmsmk"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T21:27:28.873748Z"}}