Aditya Sharma created OFBIZ-9310:
------------------------------------
Summary: On setting verbose true, UtilHttp.getParameterMap() method prints username and password in logs
Key: OFBIZ-9310
URL:
https://issues.apache.org/jira/browse/OFBIZ-9310 Project: OFBiz
Issue Type: Bug
Reporter: Aditya Sharma
Assignee: Aditya Sharma
In UtilHttp.getParameterMap(HttpServletRequest request, Set<? extends String> nameSet, Boolean onlyIncludeOrSkip) method, following line of code prints username and password in logs when verbose is set to true.
if (Debug.verboseOn()) {
Debug.logVerbose("Made Request Parameter Map with [" + paramMap.size() + "] Entries", module);
Debug.logVerbose("Request Parameter Map Entries: " + System.getProperty("line.separator") + UtilMisc.printMap(paramMap), module);
}
--
This message was sent by Atlassian JIRA
(v6.3.15#6346)