Untriaged
Jans CLI stores plaintext passwords in the local cli_cmd.log file
The Janssen Project is an open-source identity and access management (IAM) platform. In versions 1.9.0 and below, Janssen stores passwords in plaintext in the local cli_cmd.log file. This is fixed in the nightly prerelease.
References
-
https://github.com/JanssenProject/jans/security/advisories/GHSA-2f4x-m695-jvp3 x_refsource_CONFIRM
-
https://github.com/JanssenProject/jans/discussions/11886 x_refsource_MISC
-
https://github.com/JanssenProject/jans/pull/11903 x_refsource_MISC
Affected products
jans
- ==< nightly
Matching in nixpkgs
pkgs.jansson
C library for encoding, decoding and manipulating JSON data
Package maintainers
-
@9R 9R <nix@9-r.net>
-
@getchoo Seth Flynn <getchoo@tuta.io>