Skip to content

multi/manage/sudo writes clear text password to world-readable file in /tmp/ #16074

Open
@bcoles

Description

@bcoles

multi/manage/sudo performs automatic cleanup, but there's still a window of exposure.

In a worst case scenario, the password is present and readable for 120 seconds.

::Timeout.timeout(120) do

Highlighted in #13886 (comment) but never addressed.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugmodulenot-staleLabel to stop an issue from being auto closed

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions