Skip to content

Potential vulnerability when setting sensitive config ( bash history ) #146

Open
@rostilos

Description

@rostilos

Issue in ./help/configuration/cli/set-configuration-values.md

bin/magento config:sensitive:set [--scope=“...”] [--scope-code=“...”] path value
In this case I think you should remove value from the command and add it separately via prompt. I.e. remove value from the example, indicating that it can be done, but with a notation that it leaves creds in history ( bash_history ).
Even though this is a minor vulnerability, it's still a vulnerability. It is better not to leave sensetive credentials in any history.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status

    🆕 Ready for Grooming

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions