www-infrastructure-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Nick Wellnhofer (JIRA)" <j...@apache.org>
Subject [jira] Created: (INFRA-3209) JIRA sends plaintext password in confirmation email
Date Thu, 18 Nov 2010 12:22:15 GMT
JIRA sends plaintext password in confirmation email

                 Key: INFRA-3209
                 URL: https://issues.apache.org/jira/browse/INFRA-3209
             Project: Infrastructure
          Issue Type: Improvement
      Security Level: public (Regular issues)
          Components: JIRA
            Reporter: Nick Wellnhofer
            Priority: Minor

When I signed up for Apache JIRA, I was surprised to see that the confirmation email contained
the password I had chosen in plaintext. From a security standpoint it's a bad idea to send
plaintext passwords by email.

This message is automatically generated by JIRA.
You can reply to this email to add a comment to the issue online.

View raw message