-
Notifications
You must be signed in to change notification settings - Fork 46
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Apigee Developer Portal Kickstart 9.5.11 version - Not Encrypting client credentials from client browser to network #1104
Comments
Hi @mnimakwala Thanks for bringing this to our eyes, we will have a internal discussion on it and will update here. |
Hi Kedar, Thanks for picking this up. We are eagerly looking for solution to this issue. Thanks, |
Hi @mnimakwala To be very clear, this issue occurs on all Drupal versions, I checked. In the mean time, if you are having solution for this issue, we are open for your contribution on this. Thanks! |
Hi Kedar, Thanks for your quick update.
Awaiting you quick response. Thanks, |
Hi @mnimakwala For 1st - Using Drupal forms also provide same output, if you can see the user module is still in use with the points you mentioned. For 2nd - The 1st link is not working - so cannot refer the point & for your issue, Jay has already created the issue on Drupal core module 'user', so if it the changes are added by Drupal community there, we can also test the same in our forms. For 3rd - I wanted to say that, we can consider for next to next release, but currently there is no solution resolution present for it, so it is not yet evaluated for grooming also. Once we achieve that, then with proper solution, it will be discussed here. Thanks! |
Description
We have installed Apigee Developer Portal Kickstart version 9.5.11. We have observed that this module does not do encryption of user password when request is traveling from user's browser to network. At network we have enabled TLS so it request is encrypted. This leaves us in a situation to a vulnerable product. Can we enable encryption. If yes please guide. If not please share valid reason. Any plan for future releases?
Apigee Info
We are using Apigee OPDK version 4.52.00.
Steps to Reproduce
Steps to reproduce the behavior:
Actual Behavior
User password in plain text is visible in Payload option.
Expected Behavior
User password is expected to be visible in encrypted format.
Screenshots
NA
Notes
In any compliance driven industry this kind of behavior is prone to vulnerable
Version Info
Apigee Developer Portal Kickstart version - 9.5.11
Apigee version - 4.52.00
If any more details required please ask.
Thanks,
Mustufa
The text was updated successfully, but these errors were encountered: