Audit Logs Store LDAP Password in Plain Text

XMLWordPrintable

    • 1
    • Severity 2 - Major
    • 0

      Problem

      In Confluence, when an external LDAP directory is created/modified, Audit logs store the LDAP connection password as plain text.

      Environment

      7.4.x
      .

      Steps to Reproduce

      1. In Confluence, create or modify a directory as Microsoft Active Directory, Crowd, Jira etc
      2. After creation, synchronize the users.
      3. Check the Audit logs for the Directory changes and expand.
      4. Along with LDAP attribute details, we can also see that the password for external LDAP is displayed in plain text.

      Expected Results

      Passwords should be sanitised before being logged in audit log.

      Actual Results

      We are able to see the LDAP password displayed in plain text.

      Workaround

      NA

      Notes

              Assignee:
              Unassigned
              Reporter:
              Sathya Ganeshan
              Votes:
              1 Vote for this issue
              Watchers:
              8 Start watching this issue

                Created:
                Updated:
                Resolved: