[SECURITY] Hardcode the password in KeyManagerProxy
Open
help wanted
lifecycle/stale
Stale
type/bug
- Dominant language
- Java
- Stars
- 15.3k
- Forks
- 3.8k
- Avg merge
- 1d 14h
- Merged PRs (30d)
- 160
Description
https://github.com/apache/pulsar/blob/64dc5374b6f6eb59a69a036697e16c8b21a31b16/pulsar-common/src/main/java/org/apache/pulsar/common/util/KeyManagerProxy.java#L50
Is it ok to hardcode the password in KeyManagerProxy? It may have a security risk
Contributor guide
Assessment
This issue has not been assessed yet.