Redis password is dumped into the generated troubleshooting archives
Package
Tuleap Community Edition
(tuleap)
Affected versions
< 16.4.99.1740492866
Patched versions
16.4.99.1740492866
Tuleap Enterprise Edition
(tuleap)
< 16.4-6
< 16.3-11
16.4-6
16.3-11
Impact
The password to connect the Redis instance is not purged from the archive generated with
tuleap collect-system-data
. These archives are likely to be used by support teams that should not have access to this password.Patches
The following versions contain the fix:
For more information
If you have any questions or comments about this advisory, reach out to us via the contact information provided on the Tuleap.org security page.
References