Comment 1 for bug 1343604

Revision history for this message
Grant Murphy (gmurphy) wrote : Re: Exceptions thrown by execute() return a command that potentially includes passwords

Thanks for your bug report. It does look like this could lead to information leakage in the exception handler cases where attempts > 0 and possibly when the exception is propagated up (when attempts == 0).

I'm marking the OSSA bug task as incomplete until discussed with other VMT members as to whether we will issue an advisory for this problem.