Uploaded image for project: 'Bitbucket Data Center'
  1. Bitbucket Data Center
  2. BSERV-5362

Stash email settings fields can be inadvertently be populated by browser with user login details - security issue

    XMLWordPrintable

Details

    Description

      The email and username password in the email server settings screen has the same names as the username and password fields when logging in.

      This has the unintentional side affect of being pre-populated by your browser if you have left the mail server credentials blank and your browser has saved your login credentials.

      Changing another element on the form (in our case, email from), and not noticing the username and password fields have been auto-populated, results in your director's password being saved as the mail server password, and being available to all admins, in plain-text (via inspect source) next time the page loads.

      Fix: don't use the same field names (username and password) for the login field and email server settings.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              8a907ef2bbd7 Joe Bowman
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: