continuum-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Carlos Sanchez (JIRA)" <j...@codehaus.org>
Subject [jira] Commented: (CONTINUUM-2314) Password is printed in logs in clear text when adding a project fails
Date Sun, 26 Jul 2009 01:16:50 GMT

    [ http://jira.codehaus.org/browse/CONTINUUM-2314?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=184887#action_184887
] 

Carlos Sanchez commented on CONTINUUM-2314:
-------------------------------------------

seems so

> Password is printed in logs in clear text when adding a project fails
> ---------------------------------------------------------------------
>
>                 Key: CONTINUUM-2314
>                 URL: http://jira.codehaus.org/browse/CONTINUUM-2314
>             Project: Continuum
>          Issue Type: Bug
>          Components: Security
>    Affects Versions: 1.3.3
>            Reporter: Carlos Sanchez
>            Priority: Blocker
>             Fix For: 1.3.4
>
>
> I got this in the continuum log, I've changed the parameters to hide the info, but where
I say PASSWORDINCLEARTEXT it had my password there 
> Actually it had a bad password with a typo (that's why I got unauthorized) but it was
close enough to the real one
> 2009-07-24 16:03:54,137 [addMavenTwoProjectBackgroundThread] INFO  org.apache.maven.continuum.project.builder.maven.MavenTwoContinuumProjectBuilder
 - Downloading https://myusername:*****@svn.company.com/repos/pom.xml
> 2009-07-24 16:03:55,392 [addMavenTwoProjectBackgroundThread] ERROR org.apache.maven.continuum.project.builder.maven.MavenTwoContinuumProjectBuilder
 - Error
>  adding project: Unauthorized https://myusername:PASSWORDINCLEARTEXT@svn.company.com/repos/pom.xml

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://jira.codehaus.org/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

Mime
View raw message