Looks like the wrong patch was committed in #1267212: Password hash leakage.

_system_resource_connect is still leaking the password hash. I've attached a couple of ways of fixing this.

CommentFileSizeAuthor
remove_pass_3.patch435 byteswedge
remove_pass_2.patch493 byteswedge
remove_pass_1.patch407 byteswedge

Comments

wedge’s picture

Status: Active » Needs review
marcingy’s picture

Status: Needs review » Reviewed & tested by the community

Number 2 looks good to me.

kylebrowning’s picture

Status: Reviewed & tested by the community » Fixed

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.