Project

General

Profile

Actions

Bug #50451

closed

mgr/dashboard: While changing the password in Dashboard, username and Password is clearly visible in developer tools

Added by Nizamudeen A about 3 years ago. Updated almost 3 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Component - Services & Daemons
Target version:
-
% Done:

0%

Source:
Tags:
security
Backport:
octopus, pacific
Regression:
No
Severity:
3 - minor
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

Username password are sending in the URL string

{"POST":{"scheme":"https","host":"10.8.128.45:8443","filename":"/api/user/validate_password","query":{"password":"admin456","username":"admin123"},"remote":{"Address":"10.8.128.45:8443"}}}

Password is visible in the body of the request.


Files

dev.png (14 KB) dev.png Nizamudeen A, 04/21/2021 08:04 AM

Related issues 2 (0 open2 closed)

Copied to Dashboard - Backport #50475: octopus: mgr/dashboard: While changing the password in Dashboard, username and Password is clearly visible in developer toolsResolvedNizamudeen AActions
Copied to Dashboard - Backport #50476: pacific: mgr/dashboard: While changing the password in Dashboard, username and Password is clearly visible in developer toolsResolvedAvan ThakkarActions
Actions

Also available in: Atom PDF