mahara-contributors team mailing list archive
-
mahara-contributors team
-
Mailing list archive
-
Message #09324
[Bug 1016253] [NEW] Authenticated RSS feeds should encrypt login credentials
Public bug reported:
The externalfeed block should protect user credentials when
authenticated RSS feeds are used. The blocktype in Mahara 1.8.1 appears
to store login credentials in cleartext within the database.
This presents an unfortunate vulnerability that could give access to
other systems should Mahara's database be compromised.
** Affects: mahara
Importance: Undecided
Status: New
** Tags: enhancement rss security
--
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
https://bugs.launchpad.net/bugs/1016253
Title:
Authenticated RSS feeds should encrypt login credentials
Status in Mahara ePortfolio:
New
Bug description:
The externalfeed block should protect user credentials when
authenticated RSS feeds are used. The blocktype in Mahara 1.8.1
appears to store login credentials in cleartext within the database.
This presents an unfortunate vulnerability that could give access to
other systems should Mahara's database be compromised.
To manage notifications about this bug go to:
https://bugs.launchpad.net/mahara/+bug/1016253/+subscriptions
Follow ups
-
[Bug 1016253] Re: Don't send plaintext RSS password back to browser
From: Kristina Hoeppner, 2014-11-24
-
[Bug 1016253] Re: Don't send plaintext RSS password back to browser
From: Aaron Wells, 2013-05-03
-
[Bug 1016253] Re: Don't send plaintext RSS password back to browser
From: Aaron Wells, 2013-05-02
-
[Bug 1016253] Re: Authenticated RSS feeds should encrypt login credentials
From: Aaron Wells, 2013-05-02
-
[Bug 1016253] Re: Authenticated RSS feeds should encrypt login credentials
From: Aaron Wells, 2013-04-19
-
[Bug 1016253] Re: Authenticated RSS feeds should encrypt login credentials
From: Son Nguyen, 2013-01-23
-
[Bug 1016253] Re: Authenticated RSS feeds should encrypt login credentials
From: Son Nguyen, 2013-01-22
-
[Bug 1016253] Re: Authenticated RSS feeds should encrypt login credentials
From: Kristina Hoeppner, 2012-11-25
-
[Bug 1016253] Re: Authenticated RSS feeds should encrypt login credentials
From: Hugh Davenport, 2012-08-12
-
[Bug 1016253] Re: Authenticated RSS feeds should encrypt login credentials
From: Son Nguyen, 2012-07-26
-
[Bug 1016253] Re: Authenticated RSS feeds should encrypt login credentials
From: Son Nguyen, 2012-07-25
-
[Bug 1016253] Re: Authenticated RSS feeds should encrypt login credentials
From: Kristina Hoeppner, 2012-07-06
-
[Bug 1016253] Re: Authenticated RSS feeds should encrypt login credentials
From: Hugh Davenport, 2012-06-24
-
[Bug 1016253] Re: Authenticated RSS feeds should encrypt login credentials
From: Darren James Harkness, 2012-06-22
-
[Bug 1016253] Re: Authenticated RSS feeds should encrypt login credentials
From: Richard Mansfield, 2012-06-21
-
[Bug 1016253] Re: Authenticated RSS feeds should encrypt login credentials
From: Darren James Harkness, 2012-06-21
-
[Bug 1016253] [NEW] Authenticated RSS feeds should encrypt login credentials
From: Darren James Harkness, 2012-06-21
References