Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-38609

Crowd User Directory application password stored in plain text

    XMLWordPrintable

Details

    Description

      Table: cwd_directory_attribute
      Column: attribute_value

      How to Verify (in my environment):
      Connect to JIRA database using psql and run query:

      select attribute_value from cwd_directory_attribute where attribute_name = 'application.password'
      

      Note how the returned value is the plain text value of the password you entered when defining the user directory in JIRA

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              a09a4d781816 William Crighton [CCC]
              Votes:
              1 Vote for this issue
              Watchers:
              7 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: