Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-45612

Active Directory/LDAP credentials stored in database in cleartext

    XMLWordPrintable

Details

    Description

      We use an Active Directory server for authenticating our JIRA users, and a MySQL server for storing our JIRA data.

      We were extremely alarmed to discover that the username and password used for accessing the AD server are stored in cleartext in the MySQL database.

      Anyone who is able to compromise the JIRA database would then be able obtain broader credentials on the network.

      Since our JIRA database is hosted on a different machine than the JIRA application, it would be significantly more secure for the password to be enciphered with a key stored on the application's host machine.

      We have mitigated this threat by using an account that has very limited permissions, but this still poses an unacceptable risk to our information security.

      We strongly urge Atlassian to implement some sensible encryption of the LDAP/AD credentials such as suggested above.

      Attachments

        Issue Links

          Activity

            People

              pprzytarski Pawel Przytarski
              7fe2d65b7323 Luke Goodsell
              Votes:
              9 Vote for this issue
              Watchers:
              24 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: