Uploaded image for project: 'Bitbucket Cloud'
  1. Bitbucket Cloud
  2. BCLOUD-13726

Credentials that appear URL-encoded in logs are not masked

    XMLWordPrintable

Details

    Description

      I erased the actual password but it's in plaintext anyone who can push to a repo that has git in its pipelines can read any secured fields like this.

      EDIT: The password in question had a space in it, and the space was converted to %20. But that's really close to the original password.

      Also it didn't work, probably because of the %20.

      Attachments

        Activity

          People

            Unassigned Unassigned
            1ac2c1ead027 lordc
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: