Compass Password should not be displayed in Clear Text in the connection string

XMLWordPrintableJSON

    • Type: Bug
    • Resolution: Fixed
    • Priority: Critical - P2
    • 1.21.0
    • Affects Version/s: None
    • Component/s: Compass
    • None
    • Iteration Vicuña, Iteration Wombat
    • None
    • None

      Security issue

      If Compass is open and user clicks on a connection Favorite, any password embedded in the connection string is displayed in Clear Text.  The password can be stolen or if the computer display is projected or shared.

      Even with the use of LDAP authentication, the password is displayed in clear text defeating high security compliance policies.

       

            Assignee:
            Alena Khineika
            Reporter:
            Felicia Hsieh
            Votes:
            0 Vote for this issue
            Watchers:
            7 Start watching this issue

              Created:
              Updated:
              Resolved: