Project

General

Profile

Bug #19169

CVE-2017-2672 - audit trail leaks sensitive data for Image events

Added by Daniel Kimsey over 1 year ago. Updated 2 months ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
Audit Log
Target version:
Difficulty:
Triaged:
Bugzilla link:
Team Backlog:
Fixed in Releases:
Found in Releases:

Description

If one looks at an audit record for Image creation, the password used is recorded in plaintext. This must be censored.

The attached image is rendered from a specific audit entry, such as: https://katello.acme.com/audits/1234


Related issues

Related to Foreman - Refactor #20116: Redact sensitive information from audit logsNew2017-06-27
Related to Foreman - Refactor #21920: Refactor password auditingClosed2017-12-10

Associated revisions

Revision 02489389 (diff)
Added by Marek Hulán over 1 year ago

Fixes #19169 - remove image password from audit

Revision bae2fa2b (diff)
Added by Marek Hulán over 1 year ago

Fixes #19169 - remove image password from audit

History

#1 Updated by Marek Hulán over 1 year ago

  • Category changed from Web Interface to Audit Log

#2 Updated by The Foreman Bot over 1 year ago

  • Status changed from New to Ready For Testing
  • Assignee set to Marek Hulán
  • Pull request https://github.com/theforeman/foreman/pull/4438 added

#3 Updated by Dominic Cleal over 1 year ago

  • Subject changed from audit trail leaks sensitive data for Image events to CVE-2017-2672 - audit trail leaks sensitive data for Image events

Report forwarded to , CVE-2017-2672 was assigned to identify the vulnerability.

#4 Updated by Marek Hulán over 1 year ago

  • Target version set to 1.13.0

#5 Updated by Marek Hulán over 1 year ago

  • Status changed from Ready For Testing to Closed
  • % Done changed from 0 to 100

#6 Updated by Daniel Lobato Garcia over 1 year ago

  • Legacy Backlogs Release (now unused) set to 209

Setting to 1.15, it'll be cherry-picked for RC2.

#7 Updated by Bryan Kearney over 1 year ago

  • Bugzilla link set to 1447510

#8 Updated by Tomer Brisker about 1 year ago

  • Related to Refactor #20116: Redact sensitive information from audit logs added

#9 Updated by Michael Moll 9 months ago

Also available in: Atom PDF