Security Information disclosed in Service detail screen

Description

Creating issue on behalf of a support customer, see https://mynms.opennms.com/Ticket/Display.html?id=2778. Restricting visibility until fixed. Body of ticket follows.

We have a Page Sequence Monitor that is using user id and password information and this information is shown to our NOC members on the following page, opennms/element/service.jsp Attached is screen shot of what I am describing (security details masked out).

Ideally, it would be good to have all the page sequence info except for this
information shown in the service details. This is an especially bad scenario if you had Anonymous access enabled for the site. For now, we have to restrict who can have access to openNMS. This user restriction is the only reason I have marked this as minor since there are concievably work-arounds but other customers can reasonably argue this is more serious.

Acceptance / Success Criteria

None

Attachments

1
  • 13 Feb 2014, 09:24 AM

Lucidchart Diagrams

Activity

Show:

Gabriela Lopez January 30, 2023 at 6:32 PM

Information Security assessed as a low risk.

CVSS: 5.9 x low likelihood .5 = 3.0

AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N/E:F/RL:O/RC:C/CR:H/IR:H/AR:H/MAV:A/MAC:X/MPR:X/MUI:X/MS:X/MC:X/MI:X/MA:X

Alejandro Galue February 20, 2014 at 12:00 PM

Fixed on revision 3ac9f0b1215978b2ff20c59c2703fef7805cab41 for 1.12

Fixed

Details

Assignee

Reporter

Fix versions

Affects versions

Priority

PagerDuty

Created February 13, 2014 at 9:24 AM
Updated January 30, 2023 at 6:32 PM
Resolved February 20, 2014 at 12:00 PM

Flag notifications