[ 
https://issues.apache.org/jira/browse/CAMEL-12480?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16464207#comment-16464207
 ] 

ASF GitHub Bot commented on CAMEL-12480:
----------------------------------------

PascalSchumacher opened a new pull request #2317: CAMEL-12480: 
HttpOperationFailedException exposes password when using…
URL: https://github.com/apache/camel/pull/2317
 
 
   … basic auth with user:password@host notation
   
   Sanitize URI in HttpOperationFailedException constructor.

----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on GitHub and use the
URL above to go to the specific comment.
 
For queries about this service, please contact Infrastructure at:
[email protected]


> HttpOperationFailedException exposes password when using basic auth with 
> user:password@host notation
> ----------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-12480
>                 URL: https://issues.apache.org/jira/browse/CAMEL-12480
>             Project: Camel
>          Issue Type: Bug
>          Components: camel-http-common
>    Affects Versions: 2.21.0
>            Reporter: Pascal Schumacher
>            Priority: Minor
>             Fix For: 2.20.4, 2.21.2, 2.22.0
>
>
> Simplified route:
> {code}
> from(inUri)
>             .toD("http4://user:password@host:port/path");
> {code}
> When a HttpOperationFailedException occurs the message contains the unmasked 
> password e.g. "HTTP operation failed invoking 
> http://user:password@host:port/path ..."
> I guess Camel should mask the password.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

Reply via email to