h2oai / steam

DEPRECATED Build, manage and deploy H2O's high-speed machine learning models.
http://www.h2o.ai/download/
GNU Affero General Public License v3.0
61 stars 30 forks source link

Passwords are logged in plain text by web server #392

Open KrashLeviathan opened 5 years ago

KrashLeviathan commented 5 years ago

Creating a new Steam user results in the new username and password logged in the server output. Even if the credentials were encrypted, they should never be logged anywhere, as this presents a significant security vulnerability. See screenshot below:

screenshot from 2018-10-31 16-06-52