Uploaded image for project: 'MariaDB Server'
  1. MariaDB Server
  2. MDEV-7456

Server audit: Empty password in CHANGE MASTER is not obfuscated

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Major
    • Resolution: Fixed
    • Affects Version/s: N/A
    • Fix Version/s: 5.5.42
    • Component/s: Plugin - Audit
    • Labels:

      Description

      MariaDB [test]> stop slave;
      Query OK, 0 rows affected (0.13 sec)
      
      MariaDB [test]> change master to master_password='a';
      Query OK, 0 rows affected (0.35 sec)
      
      MariaDB [test]> change master to master_password='';
      Query OK, 0 rows affected (0.38 sec)
      
      20150114 16:30:42,wheezy-64,root,localhost,2,30,QUERY,test,'stop slave',0
      20150114 16:30:43,wheezy-64,root,localhost,2,31,QUERY,test,'change master to master_password=*****',0
      20150114 16:30:46,wheezy-64,root,localhost,2,32,QUERY,test,'change master to master_password=\'\'',0
      

        Gliffy Diagrams

          Attachments

            Activity

            There are no comments yet on this issue.

              People

              • Assignee:
                holyfoot Alexey Botchkov
                Reporter:
                elenst Elena Stepanova
              • Votes:
                0 Vote for this issue
                Watchers:
                1 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:

                  Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0 minutes
                  0m
                  Logged:
                  Time Spent - 1 hour
                  1h