Uploaded image for project: 'Hawkular'
  1. Hawkular
  2. HAWKULAR-603

Command Gateway should not forward passwords sent by feeds to the UI

    XMLWordPrintable

Details

    • Bug
    • Resolution: Done
    • Major
    • 1.0.0.Alpha5
    • None
    • Bus
    • None

    Description

      As discovered when writing org.hawkular.cmdgw.ws.test.CommandGatewayITest.testExecuteOperation() test, the messages sent by a feed are delivered unredacted to the UI - i.e. containing

      authentication:{"username":"jdoe","password":"password"}
      

      This is a clear security issue that could allow the UI to impersonate the feed.

      Attachments

        Issue Links

          Activity

            People

              jmazzitelli John Mazzitelli
              ppalaga Peter Palaga
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: