Session expiry pages may echo password in clear text

XMLWordPrintable

    • 5.01
    • 2.6

      The "session expiry" and "XSRF token missing" pages will echo any submitted values. This may result in echoing the submitted password to the page in plain text if triggered on the WebSudo authentication page.

      Modify the error pages (session_expired.jsp and xsrf_missing.jsp) so they don't echo parameters whose names contain password.

      To reproduce, go to a wedsudo prompt, then log out in another tab, then submit the websudo form. Your password will be echoed back to you.

            Assignee:
            Oswaldo Hernandez (Inactive)
            Reporter:
            Richard Sadd
            Votes:
            6 Vote for this issue
            Watchers:
            21 Start watching this issue

              Created:
              Updated:
              Resolved: