Hi all,
We use M365 API for monitoring. To access the API, we use username and password for authentication.
Observed today that the log file Veeam.Archiver.REST_<date>.log file has the URL printed along with username and password in clear text.
I understand that our way of access by passing password in is not the best way, but I would have expected the password to be removed while writing it in the log file.
Verified it is the same with the latest 7.1.0.2031 patch.
-
- Service Provider
- Posts: 144
- Liked: 25 times
- Joined: Apr 23, 2021 6:40 am
- Full Name: Sumeet P
- Contact:
-
- Product Manager
- Posts: 9568
- Liked: 2539 times
- Joined: May 13, 2017 4:51 pm
- Full Name: Fabian K.
- Location: Switzerland
- Contact:
Re: Password printed in Archiver REST log
Hi Sumeet
May I ask how you access the REST API? Where are you providing the passwords? In the request body or as part of the URL?
How does the log look like? Can you share the log snippet with me (replace the passwords)?
Credentials should never be logged in our log files if it was implemented correctly. Could it be that you may face the same situation as we had in this topic.
Best,
Fabian
May I ask how you access the REST API? Where are you providing the passwords? In the request body or as part of the URL?
How does the log look like? Can you share the log snippet with me (replace the passwords)?
Credentials should never be logged in our log files if it was implemented correctly. Could it be that you may face the same situation as we had in this topic.
Best,
Fabian
Product Management Analyst @ Veeam Software
-
- Service Provider
- Posts: 144
- Liked: 25 times
- Joined: Apr 23, 2021 6:40 am
- Full Name: Sumeet P
- Contact:
Re: Password printed in Archiver REST log
Hi Fabian,
Thanks for pointing it out, you are correct, it is issue with my script. I have fixed it now and passwords no longer are logged in the file.
Appreciate your quick help.
Regards,
-Sumeet.
Thanks for pointing it out, you are correct, it is issue with my script. I have fixed it now and passwords no longer are logged in the file.
Appreciate your quick help.
Regards,
-Sumeet.
-
- Product Manager
- Posts: 9568
- Liked: 2539 times
- Joined: May 13, 2017 4:51 pm
- Full Name: Fabian K.
- Location: Switzerland
- Contact:
Re: Password printed in Archiver REST log
Hi Sumeet
You‘re most welcome.
Best,
Fabian
You‘re most welcome.
Best,
Fabian
Product Management Analyst @ Veeam Software
Who is online
Users browsing this forum: No registered users and 8 guests