This bug has been fixed as part of the fix for Bug 1567186: More
thorough checking for passwords in stacktraces
The patch that did the fixing is here:
https://reviews.mahara.org/#/c/6335/5
** Changed in: mahara
Status: Confirmed => Fix Committed
** Changed in: mahara
Status: Fix Co
** Changed in: mahara
Milestone: 16.04.1 => 16.04.2
--
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
Matching subscriptions: Subscription for all Mahara Contributors -- please ask
on #mahara-dev or mahara.org forum before e
** Changed in: mahara/15.10
Milestone: 15.10.3 => 15.10.4
--
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
Matching subscriptions: Subscription for all Mahara Contributors -- please ask
on #mahara-dev or mahara.org forum be
** Changed in: mahara/15.10
Milestone: 15.10.2 => 15.10.3
--
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
Matching subscriptions: Subscription for all Mahara Contributors -- please ask
on #mahara-dev or mahara.org forum be
** No longer affects: mahara/1.10
** Changed in: mahara
Milestone: 16.04.0 => 16.04.1
--
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
Matching subscriptions: Subscription for all Mahara Contributors -- please ask
on #maha
Correction, on further analysis of the code, you don't have to have
enabled user auto-creation or sync in order to be affected by this bug.
Before the LDAP auth plugin tries to authenticate a username and
password, it connects to the server using the Mahara bind DN & password
(or anonymously) and r
This bug is similar to Bug 1009262 (User passwords logged when LDAP
misconfigured), but in this case it's logging the password that Mahara
itself uses to bind to the LDAP server. Specifically, that's field 8 on
this manual page:
manual.mahara.org/en/15.10/administration/institutions.html#index-17
** Information type changed from Public to Public Security
--
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
Matching subscriptions: Subscription for all Mahara Contributors -- please ask
on #mahara-dev or mahara.org forum befor
** Changed in: mahara
Status: New => Confirmed
** Changed in: mahara
Milestone: None => 16.04.0
** Also affects: mahara/15.10
Importance: Undecided
Status: New
** Changed in: mahara/15.10
Status: New => Confirmed
** Changed in: mahara/15.10
Milestone: None => 15.
9 matches
Mail list logo