You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@cloudstack.apache.org by "lujie (Jira)" <ji...@apache.org> on 2021/03/22 01:35:00 UTC
[jira] [Resolved] (CLOUDSTACK-10423) Potential sensitive
information disclosure
[ https://issues.apache.org/jira/browse/CLOUDSTACK-10423?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
lujie resolved CLOUDSTACK-10423.
--------------------------------
Resolution: Fixed
> Potential sensitive information disclosure
> --------------------------------------------
>
> Key: CLOUDSTACK-10423
> URL: https://issues.apache.org/jira/browse/CLOUDSTACK-10423
> Project: CloudStack
> Issue Type: Bug
> Security Level: Public(Anyone can view this level - this is the default.)
> Reporter: lujie
> Priority: Major
>
> As shown at [https://github.com/apache/cloudstack/blob/bd38f0647f59e09bc0755bbf48d48fb0a21295ca/plugins/storage/image/default/src/main/java/org/apache/cloudstack/storage/datastore/lifecycle/CloudStackImageStoreLifeCycleImpl.java#L92]
> url could contain password or other sensitive information
> we have sanitized the url before logging, but when we provide a invalid URL who still have sensitive information, the url will be warped in to an exception at
> [https://github.com/apache/cloudstack/blob/bd38f0647f59e09bc0755bbf48d48fb0a21295ca/plugins/storage/image/default/src/main/java/org/apache/cloudstack/storage/datastore/lifecycle/CloudStackImageStoreLifeCycleImpl.java#L117]
> and the exception will printed at
> [https://github.com/apache/cloudstack/blob/bd38f0647f59e09bc0755bbf48d48fb0a21295ca/server/src/main/java/com/cloud/storage/StorageManagerImpl.java#L639]
> or
> [https://github.com/apache/cloudstack/blob/bd38f0647f59e09bc0755bbf48d48fb0a21295ca/server/src/main/java/com/cloud/storage/StorageManagerImpl.java#L747]
> or
> [https://github.com/apache/cloudstack/blob/bd38f0647f59e09bc0755bbf48d48fb0a21295ca/server/src/main/java/com/cloud/storage/StorageManagerImpl.java#L2472]
> or
> [https://github.com/apache/cloudstack/blob/bd38f0647f59e09bc0755bbf48d48fb0a21295ca/server/src/main/java/com/cloud/storage/StorageManagerImpl.java#L2260]
> we should provide the detail information to client without sensitive information.
--
This message was sent by Atlassian Jira
(v8.3.4#803005)