•  
      request #41870 Redis password is dumped into the generated troubleshooting archives
    Infos
    #41870
    Thomas Gerbet (tgerbet)
    2025-03-04 17:38
    2025-02-25 14:14
    43538
    Details
    Redis password is dumped into the generated troubleshooting archives

    The password to connect the Redis instance is not purged from the archive generated with tuleap collect-system-data.

    Impact

    Password to connect Redis instance is leaked in debug archives that is likely to be used by support teams that should not have access to it.

    CVSSv3.1 score: 5.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N)

    References

    CWE 538
    CVE-2025-27150

    Other
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2025-02-25
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-02-26 09:33

    CVE-2025-27150 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes