friendica / red

The Red Matrix
MIT License
214 stars 50 forks source link

All passwords of other networks exposed in pconfig table #941

Closed ghost closed 9 years ago

ghost commented 9 years ago

This is a big security issue. When an admin searches for 'password' in the pconfig table it gives all passwords of hub members from third party social networks. These are there because of crosspost plugins. I see passwords from Diaspora, Wordpress, other RedMatrix accounts and Friendica. I know this is plugin related, but because all plugins are involved and because I believe this should be resolved on a higher level, I post this issue here.

ghost commented 9 years ago

Thank you Mike for fixing this quickly. Does this also obscure the existing passwords?

I disabled the addons on my hub, removed the plain text passwords from the pconfig table and advised my hub members to change the relevant passwords. I advise other hub admin to do at least the latter one also.

I will enable these plugins again after I have time to test it.

ghost commented 9 years ago

Tested and all passwords are now encrypted. Thanks again for the quick fix Mike.

ghost commented 9 years ago

This issue was moved to redmatrix/redmatrix#2