30
Views
4
Comments
Password sent as cleartext with HTTP vulnerability
Application Type
Traditional Web

Hi,


I am using Auth0 authentication for Users and the passwords are encrypted in database.

Recently the external party has raised an issue mentioning that the configuration is allowing to store password as plain text.

I created a new user with a password and verified the database and yet seeing the User password as encrypted password.

Also I see two entries of passwords in DB stored as plaintext for which the third party did the testing.

Like to know if any one has an idea how it was done as from application its working as expected.


Thanks and Regards,

Ramya S



2023-01-25 05-43-21
Murugan S S

Hi Ramya, 

Can you check in the service center ->admin tab->Security configuration? 

2023-01-25 05-43-21
Murugan S S

Hi Ramya, 


Did you checked that?

UserImage.jpg
Ramya somashekaraiah

Hi Murugan,

Please find the screen grab below. Have enforced https in security tab and it was existing before the bug was raised.

Thanks and Regards,

Ramya S

2023-01-25 05-43-21
Murugan S S

Hi Ramya, 

Is that user creation flow in application level or user module?

Fyi please check once,

https://success.outsystems.com/support/security/outsystems_platform_server_hardening/ 

Community GuidelinesBe kind and respectful, give credit to the original source of content, and search for duplicates before posting.