[jboss-jira] [JBoss JIRA] (SECURITY-833) EXTC with timeout not properly detected by loadPassword utility in login modules

Ivo Studensky (JIRA) issues at jboss.org
Thu May 22 04:52:57 EDT 2014


Ivo Studensky created SECURITY-833:
--------------------------------------

             Summary: EXTC with timeout not properly detected by loadPassword utility in login modules
                 Key: SECURITY-833
                 URL: https://issues.jboss.org/browse/SECURITY-833
             Project: PicketBox 
          Issue Type: Bug
      Security Level: Public (Everyone can see)
          Components: JBossSX
    Affects Versions: PicketBox_4_0_20.Beta2
            Reporter: Ivo Studensky
            Assignee: Peter Skopek


Using cached external command with time out to get user credential in login modules if not properly detected as to call the external command.
Example: {EXTC:1000}/usr/bin/getmysecretpwd




--
This message was sent by Atlassian JIRA
(v6.2.3#6260)


More information about the jboss-jira mailing list