www-infrastructure-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "#asfinfra IRC Bot (JIRA)" <j...@apache.org>
Subject [jira] Commented: (INFRA-3209) JIRA sends plaintext password in confirmation email
Date Thu, 18 Nov 2010 12:30:14 GMT

    [ https://issues.apache.org/jira/browse/INFRA-3209?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=12933405#action_12933405

#asfinfra IRC Bot commented on INFRA-3209:

<pctony> We know.  Thsanks.

> JIRA sends plaintext password in confirmation email
> ---------------------------------------------------
>                 Key: INFRA-3209
>                 URL: https://issues.apache.org/jira/browse/INFRA-3209
>             Project: Infrastructure
>          Issue Type: Improvement
>      Security Level: public(Regular issues) 
>          Components: JIRA
>            Reporter: Nick Wellnhofer
>            Priority: Minor
> When I signed up for Apache JIRA, I was surprised to see that the confirmation email
contained the password I had chosen in plaintext. From a security standpoint it's a bad idea
to send plaintext passwords by email.

This message is automatically generated by JIRA.
You can reply to this email to add a comment to the issue online.

View raw message