Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Password can be read after logout #422

Open
Geisterli opened this issue Mar 11, 2022 · 2 comments
Open

Password can be read after logout #422

Geisterli opened this issue Mar 11, 2022 · 2 comments
Assignees

Comments

@Geisterli
Copy link

Geisterli commented Mar 11, 2022

Password can be read after logout

  • Passbolt Version: 3.5.0
  • Platform and Target:
    -- Operating system: Ubuntu 20.4
    -- Passbolt Docker image version: 3.5.0-ce

What you did

  • Open the detail view of a secret.
  • Click on the eye in the detail view to display the password.
  • If asked for the Passbolt credentials, enter them.
  • Wait a longer while until the automatic logout of the website.
  • The password previously viewed is still readable.
    Passbolt_blacked
    (I have blacked out some information that is not relevant to this issue.)

What you expected to happen

I expect no passwords to be displayed after the automatic logout.

@AnatomicJC AnatomicJC added the bug label Mar 11, 2022
@AnatomicJC
Copy link
Collaborator

Hi @ChristianKippingKv-rlp and thanks for reporting this issue 👍

We created an internal ticket under reference PB-14173 to handle this. We will keep you posted as soon as the fix will be published.

With best regards,

@ScarlettRain
Copy link

ScarlettRain commented Mar 23, 2024

You'll also encrypt or drop it after that ticker right? not just change the ui? not that one can change in memory stuff and it'll get visibel or just read out :P

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants