Suds log may contain vCenter session details

Bug #1471656 reported by Vipin Balachandran
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
oslo.vmware
Fix Released
High
Vipin Balachandran

Bug Description

Failure while calling vCenter SessionManager.SessionIsActive resulted in following logs:

2015-06-28 19:51:33.330 27190 ERROR suds.client [-] <?xml version="1.0" encoding="UTF-8"?>
<SOAP-ENV:Envelope xmlns:ns0="urn:vim25" xmlns:ns1="http://schemas.xmlsoap.org/soap/envelope/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/">
   <ns1:Body>
      <ns0:SessionIsActive>
         <ns0:_this type="SessionManager">SessionManager</ns0:_this>
         <ns0:sessionID>52cafa27-80de-b09c-1c1c-dbbddbf9fd5a</ns0:sessionID>
         <ns0:userName>Administrator</ns0:userName>
      </ns0:SessionIsActive>
   </ns1:Body>

Revision history for this message
Vipin Balachandran (vbala) wrote :
Changed in oslo.vmware:
status: New → In Progress
Revision history for this message
Eric Brown (ericwb) wrote :

Does the password ever get logged or just the user name? If password, probably more serious and should be marked as security bug.

Revision history for this message
Vipin Balachandran (vbala) wrote :

I tried with invalid credentials and suds is logging username and password.

Changed in oslo.vmware:
importance: Medium → High
Eric Brown (ericwb)
information type: Public → Public Security
Revision history for this message
Davanum Srinivas (DIMS) (dims-v) wrote :
Changed in oslo.vmware:
status: In Progress → Fix Committed
Changed in oslo.vmware:
milestone: none → 1.18.0
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.