Uploaded image for project: 'WORKTERRA'
  1. WORKTERRA
  2. WT-1514

PASSWORD RETURNED IN SERVER RESPONSE

    Details

    • Type: Enhancement
    • Status: Closed
    • Priority: Medium
    • Resolution: Done
    • Affects Version/s: None
    • Fix Version/s: 1.0
    • Component/s: BenAdmin
    • Labels:
      None
    • Module:
      BenAdmin - Security
    • Reported by:
      Support
    • Item State:
      Production Complete
    • Sprint:
      WT Sprint 1

      Description

      Pretorian reported an issue that password is returning is server response is potential threat to system.

      The user’s password is returned in the response from the server when an administrator creates an account for a new employee
      By sending a user password as a response during account registration, WORKTERRA increases the possibility of the password being sniffed on the wire, or compromised via local workstation access.
      When registering a new employee, the employee's default password was displayed to the registrar.

      Ideally we should not display password to administrator.

      We need to find out all possible locations in System where we are sending password to client side.

      Possible solution for this is to remove add employee popup which displays credentials.
      Configuration flag should decide whether we need to display newly added employee password in alert or not.

        Attachments

        1. Add_Employee_Enhancement.doc
          81 kB
        2. Admin login.png
          Admin login.png
          179 kB
        3. Disply password flag settings.png
          Disply password flag settings.png
          176 kB
        4. Employee credencials.png
          Employee credencials.png
          173 kB
        5. Password credencial for SEO Module.png
          Password credencial for SEO Module.png
          178 kB
        6. Password Enhancement.xls
          18 kB

          Activity

          Transition Time In Source Status Execution Times
          Vijayendra Shinde (Inactive) made transition -
          New Request Pending for Approval
          23s 1
          Vijayendra Shinde (Inactive) made transition -
          Pending for Approval Approved for Development
          4s 1
          Samir made transition -
          Approved for Development In Development
          21h 7m 1
          Swapnil Pandhare (Inactive) made transition -
          In LB Testing Reopen in Local
          8d 5h 40m 2
          Swapnil Pandhare (Inactive) made transition -
          Reopen in Local In Development
          1h 7m 2
          Swapnil Pandhare (Inactive) made transition -
          In Development In LB Testing
          20d 22h 22m 3
          Swapnil Pandhare (Inactive) made transition -
          In LB Testing Pending for Stage Approval
          3s 1
          Satya made transition -
          Pending for Stage Approval Approved for Stage
          1m 16s 1
          Chaitali Acharya (Inactive) made transition -
          Approved for Stage Stage Testing
          3d 19h 47m 1
          Chaitali Acharya (Inactive) made transition -
          Stage Testing Pending for Production Approval
          14d 23h 46m 1
          Chaitali Acharya (Inactive) made transition -
          Pending for Production Approval Approved for production
          2s 1
          Chaitali Acharya (Inactive) made transition -
          Approved for production In Production Testing
          3s 1
          Kunal Kedari (Inactive) made transition -
          In Production Testing Production Complete
          1d 3h 4m 1
          Satya made transition -
          Production Complete Closed
          54m 18s 1

            People

            Assignee:
            jennifer.leugers Jennifer Leugers
            Reporter:
            vijayendra Vijayendra Shinde (Inactive)
            Account Executive:
            David Rhodes (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            8 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved: