Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Unauthorised access of sensitive data on https://dev.azure.com/jhipster/ #24678

Closed
1997pinchu opened this issue Dec 27, 2023 · 2 comments
Closed

Comments

@1997pinchu
Copy link

Overview of the issue

During the analysis it was observed that your development application unauthorized access and disclosing sensitive data.

Motivation for or Use Case

This is disclosing username and password publically

Reproduce the error
  1. Navigate to "https://dev.azure.com/jhipster/ff00337a-468d-47ef-a623-6f7e64f027cb/_apis/build/builds/14868/logs/145"
  2. And search Username and password.
  3. You will get in page.
Suggest a Fix

It is recommended to remove sensitive data from page

JHipster Version(s)
JHipster configuration

image

Entity configuration(s) entityName.json files generated in the .jhipster directory

https://dev.azure.com/jhipster/ff00337a-468d-47ef-a623-6f7e64f027cb/_apis/build/builds/14868/logs/145

Browsers and Operating System

Firefox

@atomfrede
Copy link
Member

It prints the default and at other places well documented default accounts, which should not be used in any production environment. But yes we might remove them from the loga although they are documented elsewhere

@atomfrede
Copy link
Member

@jhipster/developers Closing this as I don't see any issue here as the builds are old, the logins are documented elsewhere anyways and the build just did a curl and thats the homepage content of a microservice.

@deepu105 deepu105 added this to the 8.2.0 milestone Mar 20, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants