Write only ***** as password in installation log file

Jens shared this problem 6 years ago
Defect Fixed

We have installed YellowFin and found the plain text password in the installation log files.


Please write only the ****** as password into the log file -- but any way, passwords should never placed into any log file :). Thanks.


Regards,


Jens

Replies (2)

photo
1

Hi Jens,

Thanks for getting in touch about this. I actually noticed this myself a couple of weeks ago when doing an installation. As far as I can tell, (not that this makes this situation any better) the passwords only get written to the install log when installing via the command line. The passwords are not written to the log when the GUI installer option is used. Anyways, I raised this internally to be addressed by our development team as soon as I found it. For your reference, the internal tracking id of the item is YFN-7341.

I fully agree with you that we should be writing ****** in there, so hopefully this can be addressed quickly! I'll let you know here as soon as I have any updates.

Thanks,

-Conner

photo
1

Hi Jens,

Just writing to let you know this has been fixed and is published in latest builds of both 7.4 and 8. You can download latest builds here.

Please download and upgrade when you get the chance, and confirm this is now working for you.

Thanks,

Mike

Leave a Comment
 
Attach a file