apache / apache/pulsar

[SECURITY] Hardcode the password in KeyManagerProxy

Open
#14,325 4 comments 0 reactions 1 assignee Claimed by @nodece View on GitHub
help wanted lifecycle/stale Stale type/bug
Dominant language
Java
Stars
15.3k
Forks
3.8k
Avg merge
1d 14h
Merged PRs (30d)
160

Description

https://github.com/apache/pulsar/blob/64dc5374b6f6eb59a69a036697e16c8b21a31b16/pulsar-common/src/main/java/org/apache/pulsar/common/util/KeyManagerProxy.java#L50

Is it ok to hardcode the password in KeyManagerProxy? It may have a security risk

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.