-
-
Notifications
You must be signed in to change notification settings - Fork 5.9k
Closed
Labels
topic/securitySomething leaks user information or is otherwise vulnerable. Should be fixed!Something leaks user information or is otherwise vulnerable. Should be fixed!
Description
- Gitea version (or commit ref): 1.13.7
- Git version: 2.14.0
- Operating system: Windows 10/Server 2012
- Database (use
[x]
):- PostgreSQL
- MySQL
- MSSQL
- SQLite
- Can you reproduce the bug at https://try.gitea.io:
- Yes (provide example URL)
- No
- Log gist:
Bad security practice of storing passwords in plain text
Description
While application does provide a warning that it stores password in plain text, I think we all agree that this is a big security issue independently from how many privileges user has.
There is an existing module modules/secret/secret.go that allows for two way encryption. Why is it not used to encrypt password values stored in app.ini and in the database in case of LDAP auth.
...
Screenshots
wULLSnpAXbWZGYDYyhWTKKspEQoaYxXyhoisqHfa1012112796
Metadata
Metadata
Assignees
Labels
topic/securitySomething leaks user information or is otherwise vulnerable. Should be fixed!Something leaks user information or is otherwise vulnerable. Should be fixed!