Skip to content

Redis connection logging prepends masking characters without removing passwords #1602

Description

@nickna

RedisConnectionFactory emits the complete Redis password in Information-level connection logs. Its apparent redaction prepends stars to the password instead of replacing the password value.

Evidence and reproduction

At source commit 2df0cded2d3d8c96db14498fd5f385fb263b24d3, the connection-attempt and successful-connection logs use:

connectionString.Replace("password=", "password=******")

For the synthetic, nonsecret input localhost:6379,password=synthetic-test-password, this evaluates to localhost:6379,password=******synthetic-test-password. The original value is still present. The attempt log checks Contains("password="), so differently cased option names can also bypass the apparent redaction entirely.

See RedisConnectionFactory.CreateConnection. This is a source-level finding with an exact formatter reproduction; no production credentials were read or printed.

Expected change

  • Avoid logging a credential-bearing raw connection string. Prefer sanitized endpoint information or the library's password-excluding serialization.
  • Apply the same policy to attempt and success logs, case-insensitive options, and other supported credential representations.
  • Assert that synthetic passwords never appear in captured logs for both successful and failed connection attempts.

Found during #1574 investigation. Searches across open and closed issues for Redis password log, Redis credentials logs, and password masking found no matching credential-log defect. #1561 requests unified parsing and assumes redaction is retained; this issue identifies the existing incorrect redaction implementation.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingsecurity

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions