Uploaded image for project: 'Geode'
  1. Geode
  2. GEODE-9805

Debug logging of Radish AUTH command in ExecutionHandlerContext.executeCommand() reveals sensitive information

    XMLWordPrintableJSON

Details

    Description

      With debug logging enabled, the ExecutionHandlerContext.executeCommand() method logs every command executed along with its arguments. In the case of the AUTH command, this results in un-redacted userId and/or password being logged, which represents a serious security issue.

      Attachments

        Issue Links

          Activity

            People

              donalevans Donal Evans
              donalevans Donal Evans
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: