bug reporting template encourages users to paste config file with passwords
Team Summary
Official summary from Nextcloud
@hanno reported an issue within the Nextcloud bug reporting template on GitHub, the original template asked persons to paste their configuration file and had a notice that sensitive content such as the database password should be removed. The reporter argued that this was not good enough and that he discovered issues containing user credentials. We've checked all reported issues and found **a total of 23 occurrences** of passwords within tickets. Those have been redacted. Also, we've adjusted the issue template to make this more clear and are offering an issue template application which automatically fills out and sanitizes sensitive information. We want to thank @hanno for reporting this back to us and help protecting our millions of users. We want however to note, that this affected an absolute minimum of users. ---- Press article (German): https://www.golem.de/news/owncloud-nextcloud-passwoerter-im-bugtracker-1704-127346.html Personal blog (English): https://blog.hboeck.de/archives/885-Passwords-in-the-Bug-Reports-OwncloudNextcloud.html Tweet: https://twitter.com/hanno/status/848832642653073412
Vulnerability Details
Technical details and impact analysis
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure