Openbravo Issue Tracking System - Retail Modules |
View Issue Details |
|
ID | Project | Category | View Status | Date Submitted | Last Update |
0045964 | Retail Modules | Web POS | public | 2021-02-26 17:07 | 2021-03-02 14:05 |
|
Reporter | lbressan | |
Assigned To | ranjith_qualiantech_com | |
Priority | high | Severity | major | Reproducibility | always |
Status | closed | Resolution | fixed | |
Platform | | OS | 5 | OS Version | |
Product Version | RR20Q4 | |
Target Version | | Fixed in Version | RR21Q2 | |
Merge Request Status | approved |
Review Assigned To | |
OBNetwork customer | Gold |
Support ticket | 22248 |
Regression level | |
Regression date | |
Regression introduced in release | |
Regression introduced by commit | |
Triggers an Emergency Pack | No |
|
Summary | 0045964: Sensitive information exposed in Openbravo.log |
Description | The SecuredJSONProcess class in the method secureExec(Writer w, JSONObject jsonsent) logs all the json processed including Sensitive information.
The customer's class: CustomerRegistrationService is extending JSONProcessSimple Class which in turn extends the SecuredJSONProcess class of the module org.openbravo.mobile.core.process.SecuredJSONProcess within which the method secureExec(Writer w, JSONObject jsonsent) has the logger line which is causing the response from the completion of the process to be logged into the log file, screenshot of the code attached in the ticket for reference. |
Steps To Reproduce | Define a class Java that extend JSONProcessSimple |
Proposed Solution | |
Additional Information | |
Tags | No tags attached. |
Relationships | |
Attached Files | Screenshot from 2021-02-26 17-57-17.png (214,731) 2021-02-26 17:07 https://issues.openbravo.com/file_download.php?file_id=15352&type=bug

|
|
Issue History |
Date Modified | Username | Field | Change |
2021-02-26 17:07 | lbressan | New Issue | |
2021-02-26 17:07 | lbressan | Assigned To | => Retail |
2021-02-26 17:07 | lbressan | File Added: Screenshot from 2021-02-26 17-57-17.png | |
2021-02-26 17:07 | lbressan | OBNetwork customer | => Gold |
2021-02-26 17:07 | lbressan | Triggers an Emergency Pack | => No |
2021-03-01 20:07 | lbressan | Support ticket | => 22248 |
2021-03-01 20:07 | lbressan | Resolution time | => 1615762800 |
2021-03-02 13:39 | ranjith_qualiantech_com | Assigned To | Retail => ranjith_qualiantech_com |
2021-03-02 13:39 | ranjith_qualiantech_com | Status | new => scheduled |
2021-03-02 13:46 | hgbot | Merge Request Status | => open |
2021-03-02 13:46 | hgbot | Note Added: 0126474 | |
2021-03-02 14:05 | hgbot | Merge Request Status | open => approved |
2021-03-02 14:05 | hgbot | Resolution | open => fixed |
2021-03-02 14:05 | hgbot | Status | scheduled => closed |
2021-03-02 14:05 | hgbot | Fixed in Version | => RR21Q2 |
2021-03-02 14:05 | hgbot | Note Added: 0126475 | |
2021-03-02 14:05 | hgbot | Note Added: 0126476 | |