[dev] security issue with latest horde.

Vilius Šumskas vilius at lnk.lt
Wed Apr 8 15:39:58 UTC 2009


> The problem is that, if you look for "password", you'll see the user's
> password and in my case, ingo vfs's driver password.
> 
> I surelly have all the debug options turned on (and should be turned
> off on production servers!), but I think passwords shouldn't be shown
> as plain text.
> 
> Can someone reproduce this ?

It's not *user's* password. It's the text string you've entered into
password field during login.

-- 
  Vilius



More information about the dev mailing list