Uploaded image for project: 'CXF'
  1. CXF
  2. CXF-6824

Logs output User Password In Plain Text at INFO level

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Duplicate
    • 2.7.16
    • None
    • logging
    • None
    • Windows server, Java 8 and Apache CXF 2.7.16.

    • Moderate

    Description

      In a http soap webservice call, the user password was output in plain text in the log at INFO level. This leads to security concerns of the application building on top it. User password is very sensitive information, it should not be at the INFO log level.

      Attachments

        Activity

          People

            coheigea Colm O hEigeartaigh
            qi.lu@emc.com Qi Lu
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: