[
https://issues.apache.org/jira/browse/KAFKA-20964?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18109592#comment-18109592
]
Shantanu commented on KAFKA-20964:
----------------------------------
PR: https://github.com/apache/kafka/pull/23312
> ScramParser flagged by security scanner
> ---------------------------------------
>
> Key: KAFKA-20964
> URL: https://issues.apache.org/jira/browse/KAFKA-20964
> Project: Kafka
> Issue Type: Bug
> Reporter: Gergely Harmadás
> Assignee: Shantanu
> Priority: Major
>
> Pasting the analysis of the security tool
> [ScramParser|https://github.com/apache/kafka/blob/trunk/metadata/src/main/java/org/apache/kafka/metadata/storage/ScramParser.java#L141-L147]
> {quote}The constructor
> {code:java}
> PerMechanismData(
> ScramMechanism mechanism,
> String configString
> ){code}
> mishandles confidential information in line 145
> {code:java}
> throw new FormatterException("Failed to decode given saltedPassword: " +
> saltedPasswordString, e);{code}
> which can compromise user privacy and is often illegal. Mishandling private
> information, such as customer passwords or social security numbers, can
> compromise user privacy and is often illegal.
> The error message is thrown after a failed Base64-decoding, so most likely
> the provided saltedPassword is a malformed input. However, it is still a
> defensive best practice to avoid echoing user-supplied credential-adjacent
> fields in error messages, since user input can’t be controlled.
> {quote}
--
This message was sent by Atlassian Jira
(v8.20.10#820010)