Untriaged
Jans CLI stores plaintext passwords in the local cli_cmd.log file
The Janssen Project is an open-source identity and access management (IAM) platform. In versions 1.9.0 and below, Janssen stores passwords in plaintext in the local cli_cmd.log file. This is fixed in the nightly prerelease.
References
- https://github.com/JanssenProject/jans/security/advisories/GHSA-2f4x-m695-jvp3 x_refsource_CONFIRM
- https://github.com/JanssenProject/jans/pull/11903/commits/5260520e8d7ce1d1b8387c71b3571f20e643f110 x_refsource_MISC
- https://github.com/JanssenProject/jans/discussions/11886 x_refsource_MISC
- https://github.com/JanssenProject/jans/security/advisories/GHSA-2f4x-m695-jvp3 x_refsource_CONFIRM
- https://github.com/JanssenProject/jans/pull/11903/commits/5260520e8d7ce1d1b8387c71b3571f20e643f110 x_refsource_MISC
- https://github.com/JanssenProject/jans/discussions/11886 x_refsource_MISC
- https://github.com/JanssenProject/jans/security/advisories/GHSA-2f4x-m695-jvp3 x_refsource_CONFIRM
- https://github.com/JanssenProject/jans/pull/11903 x_refsource_MISC
- https://github.com/JanssenProject/jans/commit/3592837764fe48b956e3140ca17b8ef7cac00a47 x_refsource_MISC
- https://github.com/JanssenProject/jans/discussions/11886 x_refsource_MISC
Affected products
jans
- ==< nightly
Matching in nixpkgs
pkgs.jansson
C library for encoding, decoding and manipulating JSON data
pkgs.home-assistant-custom-components.omnik_inverter
Omnik Inverter integration will scrape data from an Omnik inverter connected to your local network
Package maintainers
-
@9R 9R <nix@9-r.net>
-
@getchoo Seth Flynn <getchoo@tuta.io>