Show password feature should be configurable

Bug #1400872 reported by Lin Hua Cheng
10
This bug affects 2 people
Affects Status Importance Assigned to Milestone
OpenStack Dashboard (Horizon)
Fix Released
High
Cindy Lu
OpenStack Security Advisory
Won't Fix
Undecided
Unassigned

Bug Description

Horizon allows the password field to be displayed in plain text. This introduces a potential security risk. Imagine a user leaving their desktop unlock, if the user saved their password on the browser, a malicious user could go into the Login page and display the Openstack password.

The show password feature should be made configurable for operators who wants a more secure deployment of Horizon.

Tags: security
information type: Public → Public Security
Changed in horizon:
status: New → Confirmed
tags: added: security
Cindy Lu (clu-m)
Changed in horizon:
assignee: nobody → Cindy Lu (clu-m)
Changed in horizon:
importance: Undecided → High
Revision history for this message
Jeremy Stanley (fungi) wrote :

Pretty sure this is a security hardening opportunity, not a vulnerability for which we would publish an advisory, and so I have classified it accordingly.

Changed in ossa:
status: New → Won't Fix
information type: Public Security → Public
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to horizon (master)

Fix proposed to branch: master
Review: https://review.openstack.org/140862

Changed in horizon:
status: Confirmed → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to horizon (master)

Reviewed: https://review.openstack.org/140862
Committed: https://git.openstack.org/cgit/openstack/horizon/commit/?id=afbca3d4310073b3a6bf1127890fe9d756ab5418
Submitter: Jenkins
Branch: master

commit afbca3d4310073b3a6bf1127890fe9d756ab5418
Author: Cindy Lu <email address hidden>
Date: Thu Jan 8 11:39:43 2015 -0800

    Password reveal feature should be configurable

    Horizon has a password reveal eye button which allows the
    password field to be viewed in plain text. This is a security risk
    because a malicious user can check the OpenStack password at an
    unattended computer.

    Add new DISABLE_PASSWORD_REVEAL setting which is by default, False.

    DocImpact

    Change-Id: I21a2eaedbff4c1ee73d97c5674eca43c0258ca1a
    Closes-Bug: #1400872

Changed in horizon:
status: In Progress → Fix Committed
Thierry Carrez (ttx)
Changed in horizon:
milestone: none → kilo-2
status: Fix Committed → Fix Released
Thierry Carrez (ttx)
Changed in horizon:
milestone: kilo-2 → 2015.1.0
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.