Skip to content

Unencrypted credentials #40848

@indykoning

Description

@indykoning

Preconditions and environment

  • Magento 2.4.9
  • Set up Elasticsearch credentials, and Youtube credentials

Steps to reproduce

After having set up Magento with the different kinds of credentials i noticed where unlike most other API keys and passwords the Elasticsearch/Opensearch passwords and Youtube API key are saved plaintext.
When someone unauthorized manages to get read access to this data. e.g. via an old dump leaked, limited vulnerabilities or any other method. they could cause problems.

Expected result

I would expect all passwords and API keys to be encrypted so no full credentials can get exfiltrated

Actual result

A limited amount of passwords and API keys are stored plaintext

Additional information

No response

Release note

No response

Triage and priority

  • Severity: S0 - Affects critical data or functionality and leaves users without workaround.
  • Severity: S1 - Affects critical data or functionality and forces users to employ a workaround.
  • Severity: S2 - Affects non-critical data or functionality and forces users to employ a workaround.
  • Severity: S3 - Affects non-critical data or functionality and does not force users to employ a workaround.
  • Severity: S4 - Affects aesthetics, professional look and feel, “quality” or “usability”.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    Status
    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions