#35930: Database password visible on debug page (view source only)
-------------------------------------+-------------------------------------
     Reporter:  bytej4ck             |                     Type:
                                     |  Uncategorized
       Status:  new                  |                Component:
                                     |  Uncategorized
      Version:  4.1                  |                 Severity:  Normal
     Keywords:  db, password,        |             Triage Stage:
  exposed                            |  Unreviewed
    Has patch:  0                    |      Needs documentation:  0
  Needs tests:  0                    |  Patch needs improvement:  0
Easy pickings:  0                    |                    UI/UX:  0
-------------------------------------+-------------------------------------
 In debug page view, secrets are not visible due to masked with '*' but in
 view page source db password is visible:
 [[Image(https://github.com/user-attachments/assets/a7504c2e-99b4-4268
 -8eab-1858742105ec)]]

 Password length: 99
 Characters: All password requirements including all symbols.
-- 
Ticket URL: <https://code.djangoproject.com/ticket/35930>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

-- 
You received this message because you are subscribed to the Google Groups 
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion visit 
https://groups.google.com/d/msgid/django-updates/010701935413c614-c406d888-5b49-4afe-b3f7-317194a71226-000000%40eu-central-1.amazonses.com.

Reply via email to