Page MenuHomePhabricator

Verify if the dbtree password exposed in Gerrit is still in use
Closed, ResolvedPublicSecurity

Description

Hello everyone!

After reading T96499 I noticed this public link:

https://gerrit.wikimedia.org/r/c/operations/software/+/192771/1/dbtree/inc/config.php#5

It seems that kind of stuff that should not be exposed. Isn't it?

We should:

  • double-check if that password was already changed (see below comment: T280812#7024905)
  • add a comment in Gerrit to avoid to re-open this twice (done: https://w.wiki/3Dcy)

Really apologies if you already know. Maybe @Springle can help us.

Thank you so much for your time! Cheers! 💌

Event Timeline

sbassett moved this task from Incoming to Watching on the Security-Team board.
sbassett added a project: DBA.
sbassett added a subscriber: Reedy.

The current user and the current password are different from that one.

sbassett assigned this task to Marostegui.
sbassett moved this task from Triage to Done on the DBA board.
sbassett moved this task from Watching to Our Part Is Done on the Security-Team board.
sbassett added a project: Vuln-Infoleak.
sbassett changed the visibility from "Custom Policy" to "Public (No Login Required)".
sbassett changed the edit policy from "Custom Policy" to "All Users".