Skip to content

[security] MongoDB's credentials are exposed in the logs if using url-style host to connect to a replica set #3797

@emptywee

Description

@emptywee

Please, add a condition to verify if db_host has :// in it, then show the line without the password, if any.

https://github.com/StackStorm/st2/blob/master/st2common/st2common/models/db/__init__.py#L79

Thanks!

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions