Project

General

Profile

Actions

Bug #19169

closed

CVE-2017-2672 - audit trail leaks sensitive data for Image events

Added by Daniel Kimsey over 7 years ago. Updated over 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Audit Log
Target version:
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Description

If one looks at an audit record for Image creation, the password used is recorded in plaintext. This must be censored.

The attached image is rendered from a specific audit entry, such as: https://katello.acme.com/audits/1234


Files


Related issues 2 (1 open1 closed)

Related to Foreman - Refactor #20116: Redact sensitive information from audit logsNew06/27/2017Actions
Related to Foreman - Refactor #21920: Refactor password auditingClosedTomer Brisker12/10/2017Actions
Actions #1

Updated by Marek Hulán over 7 years ago

  • Category changed from Web Interface to Audit Log
Actions #2

Updated by The Foreman Bot over 7 years ago

  • Status changed from New to Ready For Testing
  • Assignee set to Marek Hulán
  • Pull request https://github.com/theforeman/foreman/pull/4438 added
Actions #3

Updated by Dominic Cleal over 7 years ago

  • Subject changed from audit trail leaks sensitive data for Image events to CVE-2017-2672 - audit trail leaks sensitive data for Image events

Report forwarded to , CVE-2017-2672 was assigned to identify the vulnerability.

Actions #4

Updated by Marek Hulán over 7 years ago

  • Target version set to 1.13.0
Actions #5

Updated by Marek Hulán over 7 years ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100
Actions #6

Updated by Daniel Lobato Garcia over 7 years ago

  • Translation missing: en.field_release set to 209

Setting to 1.15, it'll be cherry-picked for RC2.

Actions #7

Updated by Bryan Kearney over 7 years ago

  • Bugzilla link set to 1447510
Actions #8

Updated by Tomer Brisker over 7 years ago

  • Related to Refactor #20116: Redact sensitive information from audit logs added
Actions #9

Updated by Anonymous almost 7 years ago

Actions

Also available in: Atom PDF