Peter Chen created FINERACT-2131:
------------------------------------

             Summary: Server Key not masked
                 Key: FINERACT-2131
                 URL: https://issues.apache.org/jira/browse/FINERACT-2131
             Project: Apache Fineract
          Issue Type: Bug
          Components: Client, Security
            Reporter: Peter Chen


h2. Description

The application does not mask {{server_key}} located in the External Services 
section.

h2. Reproduction Steps

1- Login at https://openmf.github.io/web-app/  or   https://demo.mifos.io

2- Visit the following section in the application: *Admin → System → External 
Services → Notification External Service* and notice the server_key is visible 
in clear text.

h2. Impact Details
`server_key` visible in clear text.

h2. Remediation Advice
Remove/mask sensitive information.
 



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to