Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Duplicate
-
2.7.16
-
None
-
None
-
Windows server, Java 8 and Apache CXF 2.7.16.
-
Moderate
Description
In a http soap webservice call, the user password was output in plain text in the log at INFO level. This leads to security concerns of the application building on top it. User password is very sensitive information, it should not be at the INFO log level.