Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1420898 - The Java command line for Hawkular carries passwords when displaying process (ps)
The Java command line for Hawkular carries passwords when displaying process ...
Status: CLOSED ERRATA
Product: OpenShift Container Platform
Classification: Red Hat
Component: Hawkular (Show other bugs)
3.4.0
All Linux
unspecified Severity high
: ---
: 3.4.z
Assigned To: Matt Wringe
Peng Li
:
Depends On: 1417652 1424137 1427325 1427544
Blocks:
  Show dependency treegraph
 
Reported: 2017-02-09 14:50 EST by Matt Wringe
Modified: 2018-04-18 01:47 EDT (History)
10 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Cause: The passwords for the keystore and truststore were being passed to EAP as system properties Consequence: As system properties, they are passed to the executable in plain text as "-D" parameters. This means the passwords could be leaked via something like the 'ps' command. Fix: The passwords are now being set in a system property file. Result: The passwords are not longer able to be leaked using something like the 'ps' command.
Story Points: ---
Clone Of: 1417652
Environment:
Last Closed: 2017-02-22 13:12:02 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2017:0289 normal SHIPPED_LIVE OpenShift Container Platform 3.4.1.7, 3.3.1.14, and 3.2.1.26 bug fix update 2017-02-22 18:10:04 EST

  None (edit)
Comment 3 Troy Dawson 2017-02-10 16:12:25 EST
This is in image openshift3/metrics-hawkular-metrics:3.4.1-4 or newer
That image is now in all testing areas.
Comment 13 errata-xmlrpc 2017-02-22 13:12:02 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2017:0289

Note You need to log in before you can comment on or make changes to this bug.