Uploaded image for project: 'Accumulo'
  1. Accumulo
  2. ACCUMULO-1086

Configuration secrets exposed via thrift RPC with no authentication

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Blocker
    • Resolution: Fixed
    • None
    • 1.5.0
    • master, rpc, tserver
    • None

    Description

      Trace password, keystore passwords, and other sensitive information is available without any authentication whatsoever, in the thrift client service. What's the reason for not requiring authentication here?

      Attachments

        Activity

          People

            ecn Eric C. Newton
            ctubbsii Christopher Tubbs
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: