Bug 1428476
| Summary: | Password visible in docker pull logs | ||
|---|---|---|---|
| Product: | OpenShift Container Platform | Reporter: | Vladislav Walek <vwalek> |
| Component: | ImageStreams | Assignee: | Ben Parees <bparees> |
| Status: | CLOSED DUPLICATE | QA Contact: | Dongbo Yan <dyan> |
| Severity: | low | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 3.4.0 | CC: | aos-bugs, jokerman, mmccomas |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2017-03-03 14:44:42 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Vladislav Walek
2017-03-02 16:21:04 UTC
no, there is no way to prevent this output but the password is also visible in your build object and i imagine the same people who can see the build logs can see the build object. Hello Ben, thank you for reply. If the proxy is set up for whole environment by sysadmin and if the admin of certain project (just his project) can see the password, then it causes the security risk. Customer many times provides his environment to 3rd party, when he set up the cluster settings and leave the project to their customers. Probably, the bug should be changed then as RFE. What do you think? Thank you *** This bug has been marked as a duplicate of bug 1366795 *** |