Preconditions and environment
- Magento 2.4.9
- Set up Elasticsearch credentials, and Youtube credentials
Steps to reproduce
After having set up Magento with the different kinds of credentials i noticed where unlike most other API keys and passwords the Elasticsearch/Opensearch passwords and Youtube API key are saved plaintext.
When someone unauthorized manages to get read access to this data. e.g. via an old dump leaked, limited vulnerabilities or any other method. they could cause problems.
Expected result
I would expect all passwords and API keys to be encrypted so no full credentials can get exfiltrated
Actual result
A limited amount of passwords and API keys are stored plaintext
Additional information
No response
Release note
No response
Triage and priority
Preconditions and environment
Steps to reproduce
After having set up Magento with the different kinds of credentials i noticed where unlike most other API keys and passwords the Elasticsearch/Opensearch passwords and Youtube API key are saved plaintext.
When someone unauthorized manages to get read access to this data. e.g. via an old dump leaked, limited vulnerabilities or any other method. they could cause problems.
Expected result
I would expect all passwords and API keys to be encrypted so no full credentials can get exfiltrated
Actual result
A limited amount of passwords and API keys are stored plaintext
Additional information
No response
Release note
No response
Triage and priority