MAAS node details page shows BMC password in cleartext

Bug #1443344 reported by Mike Pontillo
14
This bug affects 2 people
Affects Status Importance Assigned to Milestone
MAAS
Fix Released
Critical
Raphaël Badin

Bug Description

The MAAS node details page shows the BMC password in cleartext.

This could be a major security issue for MAAS administrators who are viewing node details pages with people looking over their shoulder (or screen sharing, etc).

This should be shown in field that obfuscates the password (at least unless the user clicks a button to reveal it).

Related branches

Changed in maas:
milestone: none → 1.8.0
status: New → Triaged
Changed in maas:
importance: Medium → Critical
Raphaël Badin (rvb)
Changed in maas:
assignee: nobody → Raphaël Badin (rvb)
status: Triaged → In Progress
Changed in maas:
status: In Progress → Fix Committed
Changed in maas:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.