Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-29571

Session expiry pages may echo password in clear text

    XMLWordPrintable

Details

    Description

      The "session expiry" and "XSRF token missing" pages will echo any submitted values. This may result in echoing the submitted password to the page in plain text if triggered on the WebSudo authentication page.

      Modify the error pages (session_expired.jsp and xsrf_missing.jsp) so they don't echo parameters whose names contain password.

      To reproduce, go to a wedsudo prompt, then log out in another tab, then submit the websudo form. Your password will be echoed back to you.

      Attachments

        Issue Links

          Activity

            People

              ohernandez@atlassian.com Oswaldo Hernandez (Inactive)
              63f8f7971fa0 Richard Sadd
              Votes:
              6 Vote for this issue
              Watchers:
              21 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: