If the logging level is set to debugging args the full mod apreations are logged, including prehashed data. This is only accessible in the error log, and cannot be triggered or used by an external client, but should be hardended
attachment 0001-Ticket-49009-args-debug-logging-must-be-more-restric.patch
Ticket has been cloned to Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1387771
Ticket has been cloned to Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1387772
Thanks to Ludwig for pushing his fix!
master: commit 6eb1a45
389-ds-base-1.3.5 branch: commit 3987019
389-ds-base-1.3.4 branch: commit e6ba96d
389-ds-base-1.2.11 branch: commit ca0d132
Closing the ticket...
Metadata Update from @nhosoi: - Issue set to the milestone: 1.2.11.33
389-ds-base is moving from Pagure to Github. This means that new issues and pull requests will be accepted only in 389-ds-base's github repository.
This issue has been cloned to Github and is available here: - https://github.com/389ds/389-ds-base/issues/2068
If you want to receive further updates on the issue, please navigate to the github issue and click on subscribe button.
subscribe
Thank you for understanding. We apologize for all inconvenience.
Metadata Update from @spichugi: - Issue close_status updated to: wontfix (was: Fixed)
Login to comment on this ticket.