Opened 13 years ago

Last modified 13 years ago

#449 new defect

remove cleartext password in logging

Reported by: schaubr Owned by: geonetwork-devel@…
Priority: major Milestone: Future release
Component: General Version: v2.6.2
Keywords: geonetwork, logging, password Cc:

Description

Currently, the passwords used by the users to login into GeoNetwork, appear in cleartext in the (debug) logging. Especially in an environment where users login through LDAP, this is bad practice.

Example where this happens: LDAPContext.java, line 127

Change History (1)

comment:1 by fxp, 13 years ago

Milestone: v2.6.3Future release

Also happens in Jeeves request log

Note: See TracTickets for help on using tickets.