Ad Widget

Collapse

Security problem in Webfrontend (Zabbix 1.4.2)

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • qix
    Senior Member
    Zabbix Certified SpecialistZabbix Certified Professional
    • Oct 2006
    • 423

    #1

    Security problem in Webfrontend (Zabbix 1.4.2)

    When installing Zabbix 1.4.2 web frontend, step 4 "stars" out the database password and makes it invisible for people looking over your shoulder. However, page 5 (after the connection check), shows it in plain text.

    I think this behavior is not something you would want.
    Either show the password in screen 4 so the user knows he has to be cautious, or (better) remove the password field from step 5.
    With kind regards,

    Raymond
  • cstackpole
    Senior Member
    Zabbix Certified Specialist
    • Oct 2006
    • 225

    #2
    I agree. That surprised me quite a bit when I saw it in plain text. Glad no one was around at the time...

    Comment

    • qix
      Senior Member
      Zabbix Certified SpecialistZabbix Certified Professional
      • Oct 2006
      • 423

      #3
      Alexei,

      Can you fix this in the next release?
      With kind regards,

      Raymond

      Comment

      • Aly
        ZABBIX developer
        • May 2007
        • 1126

        #4
        Thanks for reporting that.
        Fixed in rev. 4954.
        Zabbix | ex GUI developer

        Comment

        • qix
          Senior Member
          Zabbix Certified SpecialistZabbix Certified Professional
          • Oct 2006
          • 423

          #5
          Thanks for the fix!
          With kind regards,

          Raymond

          Comment

          Working...