Skip to content

Security incident - sensitive data leak #16

@woznik

Description

@woznik

Hello
I discovered that when you run the CLI there are sensitive data exposed into the console:

java  -Dhttps.proxyHost=**************** -Dhttps.proxyPort=8080 -jar /usr/local/bin/aip-console-tools-cli.jar AddVersion --server-url=https://cast-webapp-***************/cast-dev-console --app-name=seata --version-name=master@51933510 --file seata-master.zip --auto-create --enable-security-dataflow --apikey=[masked]
2020-10-05 12:45:20.518 - INFO --- Searching for application 'seata' on AIP Console
2020-10-05 12:45:20.932 - INFO --- Application 'seata' not found and 'auto create' enabled. Starting application creation
2020-10-05 12:45:21.668 - INFO --- Current step is : create_delivery_folder
2020-10-05 12:45:32.486 - INFO --- Current step is : restore_triplet
2020-10-05 12:45:32.882 - INFO --- INF;2020-10-05 14:45:32,40; ** DATABASE: postgres
2020-10-05 12:45:32.882 - INFO --- INF;2020-10-05 14:45:32,44; ** PSQL_DIR: C:\Program Files\CAST\8.3\CSSAdmin\3rdParties\x64pg11\
2020-10-05 12:45:32.882 - INFO --- INF;2020-10-05 14:45:32,45; ** CONNECTIONPROFILE: C:\Users\kkuc01\AppData\Roaming\CAST\CAST\8.3\cast-ms.connectionProfiles.pmx
2020-10-05 12:45:32.882 - INFO --- INF;2020-10-05 14:45:32,37; ** HOST: HERE!!!!!
2020-10-05 12:45:32.882 - INFO --- INF;2020-10-05 14:45:32,40; ** TABLESPACE: pg_default
2020-10-05 12:45:32.882 - INFO --- INF;2020-10-05 14:45:32,39; ** USER_ID: operator
2020-10-05 12:45:32.882 - INFO --- INF;2020-10-05 14:45:32,45; ** Use SSL: N
2020-10-05 12:45:32.883 - INFO --- INF;2020-10-05 14:45:32,37; ** OVERWRITE: N
2020-10-05 12:45:32.883 - INFO --- INF;2020-10-05 14:45:32,39; ** SCHEMA_PREFIX: seata
2020-10-05 12:45:32.883 - INFO --- INF;2020-10-05 14:45:32,42; ** WORKING_DIR: C:\Users\kkuc01\AppData\Local\Temp\CAST\CAST\8.3\20201005144532seataCASTRESTORE\
2020-10-05 12:45:32.883 - INFO --- INF;2020-10-05 14:45:32,37; ** PORT: HERE!!!!!
2020-10-05 12:45:32.883 - INFO --- INF;2020-10-05 14:45:32,42; ** LOG_FILE: C:\CAST-CONSOLE\AipNode\data\logs\external_logs\83cd5f0f-f89f-4a67-92af-8ea760fc579c\restore_triplet\restore_triplet-20201005-144530.txt
2020-10-05 12:45:32.883 - INFO --- INF;2020-10-05 14:45:32,44; ** ZIP File: C:\Program Files\CAST\8.3\tools\Restore\triplet*
2020-10-05 12:45:43.457 - INFO --- INF;2020-10-05 14:45:32,95; UnZipping Started
2020-10-05 12:45:43.457 - INFO --- INF;2020-10-05 14:45:34,31; Started Processing : seata
2020-10-05 12:45:43.457 - INFO --- INF;2020-10-05 14:45:43,33; Finished Processing : seata
2020-10-05 12:45:43.457 - INFO --- INF;2020-10-05 14:45:34,25; UnZipping Finished
2020-10-05 12:45:43.457 - INFO --- INF;2020-10-05 14:45:43,33; Triplet Restoration Started : seata
2020-10-05 12:45:43.457 - INFO --- INF;2020-10-05 14:45:32,94; ____Connected to HERE!!!!! database postgres
2020-10-05 12:45:54.195 - INFO --- INF;2020-10-05 14:45:52,37; Restoration completed for Schema : seata_central
2020-10-05 12:46:15.769 - INFO --- INF;2020-10-05 14:46:10,14; Restoration completed for Schema : seata_local
2020-10-05 12:46:26.294 - INFO --- Current step is : import_preferences
2020-10-05 12:46:26.727 - INFO --- 	-logFilePath: C:\CAST-CONSOLE\AipNode\data\logs\external_logs\83cd5f0f-f89f-4a67-92af-8ea760fc579c\import_preferences\import_preferences-20201005-144621.txt
2020-10-05 12:46:26.727 - INFO --- 	-licenseKey: HERE!!!!!
2020-10-05 12:46:26.727 - INFO --- 	-sourceDeliveryFolder: C:\CAST-CONSOLE\AipNode\data\delivery\{e3eda3d2-604a-4883-aa5f-0ecb4b9abe11}
2020-10-05 12:46:26.727 - INFO --- Log file : C:\CAST-CONSOLE\AipNode\data\logs\external_logs\83cd5f0f-f89f-4a67-92af-8ea760fc579c\import_preferences\import_preferences-20201005-144621.txt
2020-10-05 12:46:26.728 - INFO --- 	-noLicenseKeyCheck: true
2020-10-05 12:46:26.728 - INFO --- Using arguments:
2020-10-05 12:46:26.728 - INFO --- 	configurePlatformPreferences
2020-10-05 12:46:26.728 - INFO --- 	-connectionProfile: seata_mngt on CastStorageService _ HERE!!!!!
2020-10-05 12:46:26.728 - INFO --- 	-sourceDeploymentFolder: U:\
2020-10-05 12:46:37.070 - INFO --- Current step is : manage_application
2020-10-05 12:46:48.312 - INFO --- 	manageAICPApplication
2020-10-05 12:46:48.312 - INFO --- 	-temporaryPath: C:\ProgramData\CAST\CAST\CASTMS
2020-10-05 12:46:48.312 - INFO --- Using arguments:
2020-10-05 12:46:48.312 - INFO --- 	-workingPath: C:\ProgramData\CAST\CAST\CASTMS
2020-10-05 12:46:48.312 - INFO --- 	-logFilePath: C:\CAST-CONSOLE\AipNode\data\logs\external_logs\83cd5f0f-f89f-4a67-92af-8ea760fc579c\manage_application\manage_application-20201005-144635.txt
2020-10-05 12:46:48.312 - INFO --- Log file : C:\CAST-CONSOLE\AipNode\data\logs\external_logs\83cd5f0f-f89f-4a67-92af-8ea760fc579c\manage_application\manage_application-20201005-144635.txt
2020-10-05 12:46:48.313 - INFO --- 	-connectionProfile: seata_mngt on CastStorageService _ cast-am-pwz-6-lnx:54329
2020-10-05 12:46:48.313 - INFO --- 	-appli: seata
2020-10-05 12:46:48.313 - INFO --- 	-logRootPath: C:\ProgramData\CAST\CAST\Logs
2020-10-05 12:46:59.027 - INFO --- Creating a new upload for application
2020-10-05 12:46:59.251 - INFO --- Starting chunks uploads. Expected number of chunks is 1
2020-10-05 12:46:59.327 - INFO --- Uploading chunk 1 of 1
2020-10-05 12:47:01.360 - INFO --- Extracting archive on AIP Console
2020-10-05 12:47:22.691 - INFO --- Successfully started Job

Do you have a way to prevent that?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions