ppkarwasz opened a new issue, #4345:
URL: https://github.com/apache/logging-log4j2/issues/4345
## Description
The JMS appender prints its `securityCredentials` in clear text in status
logger messages,
although the attribute is declared with `@PluginBuilderAttribute(sensitive =
true)`.
- `JmsAppender.Builder` passes `securityCredentials` to
`JndiManager.createProperties`,
which stores it as `Context.SECURITY_CREDENTIALS` in the `jndiProperties`
of `JmsManagerConfiguration`.
- `JmsManagerConfiguration.toString()` prints the whole `jndiProperties`
table.
- That string is logged at `ERROR` when the manager cannot be created
(`"Error creating JmsManager using JmsManagerConfiguration [{}]"`,
`JmsManager`),
i.e. at the default status logger level, on an ordinary broker outage.
- `JmsAppender.Builder.toString()` also concatenates `securityCredentials`.
The same code exists in `log4j-jakarta-jms`.
Expected behavior: mask `Context.SECURITY_CREDENTIALS` (and any password) in
both `toString()` methods,
in `log4j-core` and `log4j-jakarta-jms`.
## Configuration
**Version:** 2.26.1 (and `2.x` at `d631e82`)
**Operating system:** any
**JDK:** any
## Logs
The `ERROR` message contains `java.naming.security.credentials=` followed by
the credentials in clear text.
## Reproduction
Configure a `JMS` appender with `securityCredentials` pointing to an
unreachable broker and look at the status logger output.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]