Description
Insertion of Sensitive Information into Log File in Apache Geode Web Management.



This issue affects Apache Geode: from 2.0.0 before 2.0.3.



Users are recommended to upgrade to version 2.0.3, which fixes the issue.
Published: 2026-10-07
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

Based on the description, the vulnerability allows the Apache Geode Management REST API to log files, resulting in the inadvertent logging of potentially sensitive information. The exposure can reveal confidential data such as internal identifiers, configuration details, or other secrets that may be part of the request payload (inferred). The description indicates that the flaw originates from insufficient sanitization of input before it is logged, enabling any data included in the payload to be written to the server’s audit logs (inferred).

Affected Systems

Apache Geode Web Management releases 2.0.0 through 2.0.2 are affected. The Apache Software Foundation identifies the vulnerability in versions prior to 2.0.3, and the advisory does not indicate a wider range of products or more recent releases.

Risk and Exploitability

EPSS score of <1% indicates a low but non-zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, which suggests that no public exploit is known. The description indicates that the flaw allows remote actors with access to the Management REST API to inject arbitrary data into log files (inferred). Delivery requires the ability to send requests to the API endpoint; authentication is likely required but the exact requirement is not specified in the advisory (inferred). The CVSS score of 7.5 denotes a high severity, but the absolute risk remains significant for exposed management interfaces.

Generated by OpenCVE AI on October 8, 2026 at 18:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Apache Geode to version 2.0.3 or later, which removes the logging flaw.
  • Restrict network access to the Management REST API, ensuring only trusted hosts or services can reach the endpoint.
  • Configure or implement log sanitization to strip or mask sensitive values before logging, thereby reducing the risk of inadvertent disclosure.

Generated by OpenCVE AI on October 8, 2026 at 18:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 07 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-532

Wed, 07 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
References

Wed, 07 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Insertion of Sensitive Information into Log File in Apache Geode Web Management. This issue affects Apache Geode: from 2.0.0 before 2.0.3. Users are recommended to upgrade to version 2.0.3, which fixes the issue.
Title Apache Geode: Management REST API: Insertion of Sensitive Information into Log File
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-10-08T17:12:22.037Z

Reserved: 2026-09-30T13:03:35.003Z

Link: CVE-2026-103371

cve-icon Vulnrichment

Updated: 2026-10-07T19:07:38.142Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-07T19:17:31.453

Modified: 2026-10-08T17:26:22.830

Link: CVE-2026-103371

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T21:30:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-532

    Insertion of Sensitive Information into Log File