Project

General

Profile

Actions

Bug #50451

closed

mgr/dashboard: While changing the password in Dashboard, username and Password is clearly visible in developer tools

Added by Nizamudeen A about 3 years ago. Updated almost 3 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Component - Services & Daemons
Target version:
-
% Done:

0%

Source:
Tags:
security
Backport:
octopus, pacific
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

Username password are sending in the URL string

{"POST":{"scheme":"https","host":"10.8.128.45:8443","filename":"/api/user/validate_password","query":{"password":"admin456","username":"admin123"},"remote":{"Address":"10.8.128.45:8443"}}}

Password is visible in the body of the request.


Files

dev.png (14 KB) dev.png Nizamudeen A, 04/21/2021 08:04 AM

Related issues 2 (0 open2 closed)

Copied to Dashboard - Backport #50475: octopus: mgr/dashboard: While changing the password in Dashboard, username and Password is clearly visible in developer toolsResolvedNizamudeen AActions
Copied to Dashboard - Backport #50476: pacific: mgr/dashboard: While changing the password in Dashboard, username and Password is clearly visible in developer toolsResolvedAvan ThakkarActions
Actions #1

Updated by Nizamudeen A about 3 years ago

  • Description updated (diff)
Actions #2

Updated by Nizamudeen A about 3 years ago

  • Status changed from In Progress to Fix Under Review
  • Pull request ID set to 40954
Actions #3

Updated by Ernesto Puerta about 3 years ago

  • Status changed from Fix Under Review to Pending Backport
Actions #4

Updated by Backport Bot about 3 years ago

  • Copied to Backport #50475: octopus: mgr/dashboard: While changing the password in Dashboard, username and Password is clearly visible in developer tools added
Actions #5

Updated by Backport Bot about 3 years ago

  • Copied to Backport #50476: pacific: mgr/dashboard: While changing the password in Dashboard, username and Password is clearly visible in developer tools added
Actions #6

Updated by Ernesto Puerta almost 3 years ago

  • Status changed from Pending Backport to Resolved
Actions

Also available in: Atom PDF