Uploaded image for project: 'Infinispan'
  1. Infinispan
  2. ISPN-15202

Some credentials are serialized as part of the cache configuration

XMLWordPrintable

      When serializing the configuration for a cache to XML/JSON/YAML which contains credentials (JDBC store w with connection pooling, Remote store) the credentials are returned in clear text as part of the configuration.

      The issue's impact is limited because only users with the ADMIN permission can retrieve the cache configurations, and the recommended approach for connecting via JDBC is using the `datasource` configuration which does not expose the database credentials.

            ttarrant@redhat.com Tristan Tarrant
            ttarrant@redhat.com Tristan Tarrant
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: