Uploaded image for project: 'aaa'
  1. aaa
  2. AAA-21

Security Issue in Restconf: Restconf config output produces user name and password in clear text

    XMLWordPrintable

Details

    • Bug
    • Status: Resolved
    • Resolution: Done
    • None
    • None
    • General
    • None
    • Operating System: All
      Platform: All

    • 2251

    Description

      I mounted couple of Netconf capable devices onto the ODL controller. Once I did that I wanted to get the config output of the
      1. Entire controller ( As controller itself can be mounted as Netconf end point)
      2. The configuration of the mounted device.

      For the first one I issued the following restconf URL.

      http://10.18.161.79:8181/restconf/config/opendaylight-inventory:nodes/node/controller-config/yang-ext:mount/config:modules/

      This resulted in some configuration information of the mounted devices including the user name and password to access them.

      However the user name and password is in clear text which is a big security threat.

      Attachments

        No reviews matched the request. Check your Options in the drop-down menu of this sections header.

        Activity

          People

            Unassigned Unassigned
            bvaradar@brocade.com Balaji Varadaraju
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: