Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

In automation, when viewing an 'SNMP option set', the private passphrase is in clear #3488

Closed
arno-st opened this issue Apr 22, 2020 · 3 comments
Labels
bug Undesired behaviour confirmed Bug is confirm by dev team resolved A fixed issue
Milestone

Comments

@arno-st
Copy link
Contributor

arno-st commented Apr 22, 2020

In Cacti 1.2.11 at least
In automation, when viewing an 'SNMP option set', in snmpV3 model, the private passphrase is in clear
But when you have to enter, in the automation snmp option, it it's a 'password' type field, so not user viewable.

So in the 'SNMP option set' view, you should not be able to see it, otherwise it has nothing of private!

@arno-st arno-st added bug Undesired behaviour unverified Some days we don't have a clue labels Apr 22, 2020
@bmfmancini
Copy link
Member

I am not seeing the same thing

Cacti Version 1.2.11
Cacti OS unix
RSA Fingerprint
NET-SNMP Version NET-SNMP version: 5.7.2

image

@bmfmancini
Copy link
Member

AHHH Never Mind I see what you mean

image

@bmfmancini
Copy link
Member

Yea I submitted an issue on this yesterday on the device page the same thing happens the auth password is obfuscated but the priv is not I think they should be and maybe have a button to show the values temporarily

TheWitness added a commit that referenced this issue Apr 24, 2020
* 1.2.11 shows snmpv3 password is not obfuscated in device defaults screen
* In automation, when viewing an 'SNMP option set', the private passphrase is in clear
@TheWitness TheWitness added resolved A fixed issue and removed unverified Some days we don't have a clue labels Apr 24, 2020
@TheWitness TheWitness added this to the 1.2.12 milestone Apr 24, 2020
@netniV netniV added the confirmed Bug is confirm by dev team label Apr 26, 2020
@github-actions github-actions bot locked and limited conversation to collaborators Jul 26, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
bug Undesired behaviour confirmed Bug is confirm by dev team resolved A fixed issue
Projects
None yet
Development

No branches or pull requests

4 participants