Impact
Based on the description, the vulnerability allows the Apache Geode Management REST API to log files, resulting in the inadvertent logging of potentially sensitive information. The exposure can reveal confidential data such as internal identifiers, configuration details, or other secrets that may be part of the request payload (inferred). The description indicates that the flaw originates from insufficient sanitization of input before it is logged, enabling any data included in the payload to be written to the server’s audit logs (inferred).
Affected Systems
Apache Geode Web Management releases 2.0.0 through 2.0.2 are affected. The Apache Software Foundation identifies the vulnerability in versions prior to 2.0.3, and the advisory does not indicate a wider range of products or more recent releases.
Risk and Exploitability
EPSS score of <1% indicates a low but non-zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, which suggests that no public exploit is known. The description indicates that the flaw allows remote actors with access to the Management REST API to inject arbitrary data into log files (inferred). Delivery requires the ability to send requests to the API endpoint; authentication is likely required but the exact requirement is not specified in the advisory (inferred). The CVSS score of 7.5 denotes a high severity, but the absolute risk remains significant for exposed management interfaces.
OpenCVE Enrichment