Bug 36591 - password in logfile
password in logfile
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: UDM (Generic)
UCS 4.0
Other Linux
: P5 normal (vote)
: UCS 4.0-0-errata
Assigned To: Florian Best
Alexander Kläser
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-11-12 11:20 CET by Florian Best
Modified: 2021-06-23 07:29 CEST (History)
3 users (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional): Security
Max CVSS v3 score:
best: Patch_Available+


Attachments
patch (925 bytes, patch)
2015-01-07 17:47 CET, Florian Best
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Florian Best univentionstaff 2014-11-12 11:20:07 CET
I just created a "Computer: Trust Account" with ucr umc/module/debug/level=4.
/var/log/univention/management-console-module-udm.log contained this line:
… Setting property password to univention
Comment 1 Florian Best univentionstaff 2014-11-13 11:22:22 CET
also for DC backup, etc.
Comment 2 Florian Best univentionstaff 2015-01-07 17:47:28 CET
Created attachment 6579 [details]
patch
Comment 3 Florian Best univentionstaff 2015-01-08 17:52:37 CET
Password properties aren't logged anymore. The patch was cleaned up.

svn r57206
YAML: 2015-01-08-univention-management-console-module-udm.yaml
Reproduce: Add a computer via UMC having a password set.
Comment 4 Philipp Hahn univentionstaff 2015-01-09 11:23:57 CET
Jenkins regressions r57206:
 60_umc-system.80_umc-service-license.test	31.168	1
 60_umc-system.60_umc-service-extended-attributes.test	2.931	1
 60_umc-system.24_umc-service-create-group.test	1.682	1
 60_umc-system.23_umc-service-create-user.test	1.929	1
 53_samba-common.37_spoolss_architecture.test	0.035	1
 10_ldap.28reconnect_univention-ldapsearch.test	32.803	1

> "/usr/lib/pymodules/python2.7/univention/management/console/modules/udm/udm_ldap.py", line 392, in _map_properties\n    MODULE.info('Setting property %s to %s' % (property_name, logvalue))\nNameError: global name 'logvalue' is not defined\n"}
Comment 5 Florian Best univentionstaff 2015-01-09 11:34:56 CET
ups, sorry! fixed, package builds.
Comment 6 Alexander Kläser univentionstaff 2015-01-21 13:26:54 CET
Changes: OK
Package version: OK
YAML: OK, I did some adjustments for the entry [r57426].
Comment 7 Janek Walkenhorst univentionstaff 2015-01-29 11:45:57 CET
<http://errata.univention.de/ucs/4.0/62.html>