Continuum

Password is printed in logs in clear text when adding a project fails

Details

  • Type: Bug Bug
  • Status: Closed Closed
  • Priority: Blocker Blocker
  • Resolution: Fixed
  • Affects Version/s: 1.3.3 (Beta)
  • Fix Version/s: 1.3.4 (Beta)
  • Component/s: Security
  • Labels:
    None
  • Complexity:
    Intermediate
  • Number of attachments :
    0

Description

I got this in the continuum log, I've changed the parameters to hide the info, but where I say PASSWORDINCLEARTEXT it had my password there
Actually it had a bad password with a typo (that's why I got unauthorized) but it was close enough to the real one

2009-07-24 16:03:54,137 [addMavenTwoProjectBackgroundThread] INFO org.apache.maven.continuum.project.builder.maven.MavenTwoContinuumProjectBuilder - Downloading https://myusername:*****@svn.company.com/repos/pom.xml
2009-07-24 16:03:55,392 [addMavenTwoProjectBackgroundThread] ERROR org.apache.maven.continuum.project.builder.maven.MavenTwoContinuumProjectBuilder - Error
adding project: Unauthorized https://myusername:PASSWORDINCLEARTEXT@svn.company.com/repos/pom.xml

Activity

Hide
Brett Porter added a comment -

so it is only shown if it is wrong?

Show
Brett Porter added a comment - so it is only shown if it is wrong?
Hide
Carlos Sanchez added a comment -

seems so

Show
Carlos Sanchez added a comment - seems so
Hide
Maria Catherine Tan added a comment -

fixed in
r798376 of 1.3.x branch
r798377 of trunk

Show
Maria Catherine Tan added a comment - fixed in r798376 of 1.3.x branch r798377 of trunk
Hide
Maria Catherine Tan added a comment -

Reopening because password is still printed in logs.

Show
Maria Catherine Tan added a comment - Reopening because password is still printed in logs.
Hide
Maria Catherine Tan added a comment -

Fixed in
r800613 of 1.3.x branch
r800615 of trunk

Show
Maria Catherine Tan added a comment - Fixed in r800613 of 1.3.x branch r800615 of trunk

People

Vote (0)
Watch (0)

Dates

  • Created:
    Updated:
    Resolved: