View Issue Details

IDProjectCategoryView StatusLast Update
0010250Talerlibeufin-bankpublic2025-08-12 08:50
ReporterChristian Grothoff Assigned ToAntoine A  
PrioritynormalSeveritymajorReproducibilityhave not tried
Status assignedResolutionopen 
Platformi7OSDebian GNU/LinuxOS Versionsqueeze
Product Version1.0 
Target Version1.1 
Summary0010250: body of tan_challenges stores passwords in the clear?
DescriptionFrom my understanding (but didn't try it out), the 'body' field of tan_challenges might store the new password in cleartext when a user is given a 2-FA challenge when changing the account password. That would be very bad. I think it would suffice for us to store the hash of the body, which would be more compact and avoid the vulnerability.
Tagssecurity

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2025-08-12 08:49 Christian Grothoff New Issue
2025-08-12 08:49 Christian Grothoff Status new => assigned
2025-08-12 08:49 Christian Grothoff Assigned To => Antoine A
2025-08-12 08:50 Christian Grothoff Tag Attached: security