Bug 1420898 - The Java command line for Hawkular carries passwords when displaying process (ps)
Summary: The Java command line for Hawkular carries passwords when displaying process ...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Hawkular
Version: 3.4.0
Hardware: All
OS: Linux
unspecified
high
Target Milestone: ---
: 3.4.z
Assignee: Matt Wringe
QA Contact: Peng Li
URL:
Whiteboard:
Depends On: 1417652 1424137 1427325 1427544
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-02-09 19:50 UTC by Matt Wringe
Modified: 2020-04-15 15:15 UTC (History)
10 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Cause: The passwords for the keystore and truststore were being passed to EAP as system properties Consequence: As system properties, they are passed to the executable in plain text as "-D" parameters. This means the passwords could be leaked via something like the 'ps' command. Fix: The passwords are now being set in a system property file. Result: The passwords are not longer able to be leaked using something like the 'ps' command.
Clone Of: 1417652
Environment:
Last Closed: 2017-02-22 18:12:02 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2017:0289 0 normal SHIPPED_LIVE OpenShift Container Platform 3.4.1.7, 3.3.1.14, and 3.2.1.26 bug fix update 2017-02-22 23:10:04 UTC

Comment 3 Troy Dawson 2017-02-10 21:12:25 UTC
This is in image openshift3/metrics-hawkular-metrics:3.4.1-4 or newer
That image is now in all testing areas.

Comment 13 errata-xmlrpc 2017-02-22 18:12:02 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2017:0289


Note You need to log in before you can comment on or make changes to this bug.