ppkarwasz opened a new issue, #4345:
URL: https://github.com/apache/logging-log4j2/issues/4345

   ## Description
   
   The JMS appender prints its `securityCredentials` in clear text in status 
logger messages,
   although the attribute is declared with `@PluginBuilderAttribute(sensitive = 
true)`.
   
   - `JmsAppender.Builder` passes `securityCredentials` to 
`JndiManager.createProperties`,
     which stores it as `Context.SECURITY_CREDENTIALS` in the `jndiProperties` 
of `JmsManagerConfiguration`.
   - `JmsManagerConfiguration.toString()` prints the whole `jndiProperties` 
table.
   - That string is logged at `ERROR` when the manager cannot be created
     (`"Error creating JmsManager using JmsManagerConfiguration [{}]"`, 
`JmsManager`),
     i.e. at the default status logger level, on an ordinary broker outage.
   - `JmsAppender.Builder.toString()` also concatenates `securityCredentials`.
   
   The same code exists in `log4j-jakarta-jms`.
   
   Expected behavior: mask `Context.SECURITY_CREDENTIALS` (and any password) in 
both `toString()` methods,
   in `log4j-core` and `log4j-jakarta-jms`.
   
   
   ## Configuration
   
   **Version:** 2.26.1 (and `2.x` at `d631e82`)
   
   **Operating system:** any
   
   **JDK:** any
   
   ## Logs
   
   The `ERROR` message contains `java.naming.security.credentials=` followed by 
the credentials in clear text.
   
   ## Reproduction
   
   Configure a `JMS` appender with `securityCredentials` pointing to an 
unreachable broker and look at the status logger output.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to