Actions
Bug #26450
closedCVE-2019-3893: Compute resource delete via api returns password in plaintext
Difficulty:
Triaged:
No
Bugzilla link:
Pull request:
Updated by Tomer Brisker over 5 years ago
- Private changed from Yes to No
This can be worked around by not granting "destroy_compute_resource" permissions to users that should not know the password.
Updated by The Foreman Bot over 5 years ago
- Status changed from New to Ready For Testing
- Pull request https://github.com/theforeman/foreman/pull/6621 added
Updated by Tomer Brisker over 5 years ago
- Fixed in Releases 1.20.3, 1.21.1, 1.22.0 added
Updated by Shira Maximov over 5 years ago
- Status changed from Ready For Testing to Closed
Applied in changeset 12174920f9df7803060f8b2be9fdf3c250ab4291.
Updated by Tomer Brisker over 5 years ago
- Subject changed from Compute resource delete via api returns password in plaintext to CVE-2019-3893: Compute resource delete via api returns password in plaintext
Actions