User's password can be viewed and filtered by the logcat command after logging in to Bugzilla Lite

RESOLVED INVALID

Status

Firefox OS
Gaia::Bugzilla Lite
RESOLVED INVALID
3 years ago
2 years ago

People

(Reporter: cynthiatang, Unassigned)

Tracking

Firefox Tracking Flags

(Not tracked)

Details

Attachments

(1 attachment)

(Reporter)

Description

3 years ago
Created attachment 8648344 [details]
Log in to Bugzilla Lite

Steps to Reproduce: 
1. Use "adb logcat | grep password=" to view the log messages (PC)
2. Login to Bugzilla Lite (Smartphone)

Actual Results: 
 - User's password can be viewed and filtered. Please see the attachment.

Expected Results: 
 - User's password should not be viewed.

Updated

2 years ago
Blocks: 1180660
Fixed by https://github.com/mozilla-b2g/bzlite/commit/1f6f16165b218de7bce3c870802d0b8617f5eb53
Status: NEW → RESOLVED
Last Resolved: 2 years ago
Resolution: --- → INVALID
You need to log in before you can comment on or make changes to this bug.