RedisConnectionFactory emits the complete Redis password in Information-level connection logs. Its apparent redaction prepends stars to the password instead of replacing the password value.
Evidence and reproduction
At source commit 2df0cded2d3d8c96db14498fd5f385fb263b24d3, the connection-attempt and successful-connection logs use:
connectionString.Replace("password=", "password=******")
For the synthetic, nonsecret input localhost:6379,password=synthetic-test-password, this evaluates to localhost:6379,password=******synthetic-test-password. The original value is still present. The attempt log checks Contains("password="), so differently cased option names can also bypass the apparent redaction entirely.
See RedisConnectionFactory.CreateConnection. This is a source-level finding with an exact formatter reproduction; no production credentials were read or printed.
Expected change
- Avoid logging a credential-bearing raw connection string. Prefer sanitized endpoint information or the library's password-excluding serialization.
- Apply the same policy to attempt and success logs, case-insensitive options, and other supported credential representations.
- Assert that synthetic passwords never appear in captured logs for both successful and failed connection attempts.
Found during #1574 investigation. Searches across open and closed issues for Redis password log, Redis credentials logs, and password masking found no matching credential-log defect. #1561 requests unified parsing and assumes redaction is retained; this issue identifies the existing incorrect redaction implementation.
RedisConnectionFactoryemits the complete Redis password in Information-level connection logs. Its apparent redaction prepends stars to the password instead of replacing the password value.Evidence and reproduction
At source commit
2df0cded2d3d8c96db14498fd5f385fb263b24d3, the connection-attempt and successful-connection logs use:For the synthetic, nonsecret input
localhost:6379,password=synthetic-test-password, this evaluates tolocalhost:6379,password=******synthetic-test-password. The original value is still present. The attempt log checksContains("password="), so differently cased option names can also bypass the apparent redaction entirely.See
RedisConnectionFactory.CreateConnection. This is a source-level finding with an exact formatter reproduction; no production credentials were read or printed.Expected change
Found during #1574 investigation. Searches across open and closed issues for Redis password log, Redis credentials logs, and password masking found no matching credential-log defect. #1561 requests unified parsing and assumes redaction is retained; this issue identifies the existing incorrect redaction implementation.