Uploaded image for project: 'Infinispan'
  1. Infinispan
  2. ISPN-15202

Some credentials are serialized as part of the cache configuration

This issue belongs to an archived project. You can view it, but you can't modify it. Learn more

XMLWordPrintable

      When serializing the configuration for a cache to XML/JSON/YAML which contains credentials (JDBC store w with connection pooling, Remote store) the credentials are returned in clear text as part of the configuration.

      The issue's impact is limited because only users with the ADMIN permission can retrieve the cache configurations, and the recommended approach for connecting via JDBC is using the `datasource` configuration which does not expose the database credentials.

              ttarrant@redhat.com Tristan Tarrant
              ttarrant@redhat.com Tristan Tarrant
              Archiver:
              rhn-support-adongare Amol Dongare

                Created:
                Updated:
                Resolved:
                Archived: