Bug 1427544 - The Heapster command carries passwords when displaying process (ps)
Summary: The Heapster command carries passwords when displaying process (ps)
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Hawkular
Version: 3.2.1
Hardware: All
OS: Linux
unspecified
high
Target Milestone: ---
: 3.2.1
Assignee: Matt Wringe
QA Contact: Peng Li
URL:
Whiteboard:
Depends On: 1417652 1427325
Blocks: 1420898 1424137 1427405 1427542
TreeView+ depends on / blocked
 
Reported: 2017-02-28 14:48 UTC by Matt Wringe
Modified: 2020-04-15 15:23 UTC (History)
9 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Cause: The Heapster password was being set via a property value. Consequence: The password could be leaked by such processes as ps Fix: The password is now being set via a system property Result: The password is no longer leaked by such processes as ps
Clone Of: 1427325
Environment:
Last Closed: 2017-03-15 20:03:47 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2017:0512 0 normal SHIPPED_LIVE OpenShift Container Platform 3.4.1.10, 3.3.1.17, and 3.2.1.28 bug fix update 2017-03-16 00:01:17 UTC

Comment 2 Troy Dawson 2017-02-28 15:58:06 UTC
This fix is now available in openshift3/metrics-heapster:3.2.1-6 or newer.
This is now available on the usual testing areas.

Comment 6 errata-xmlrpc 2017-03-15 20:03:47 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2017:0512


Note You need to log in before you can comment on or make changes to this bug.