Bug #76970 [Com]: Password shown in Stacktrace

From: Date: Thu, 04 Oct 2018 13:29:52 +0000
Subject: Bug #76970 [Com]: Password shown in Stacktrace
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217408@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76970&edit=1 ID: 76970 Comment by: spam2 at rhsoft dot net Reported by: edv at aulenbacher dot de Summary: Password shown in Stacktrace Status: Open Type: Bug Package: PDO Core Operating System: Linux PHP Version: 7.2.10 Block user comment: N Private report: N New Comment: irrelevant - php stacktraces are supposed to show the params and you must not echo out debug informations to the client Previous Comments: ------------------------------------------------------------------------ [2018-10-04 13:28:11] edv at aulenbacher dot de addendum: The following constructor was used: public PDO::__construct ( string $dsn, string $username, string $passwd) ------------------------------------------------------------------------ [2018-10-04 13:24:56] spam2 at rhsoft dot net this is *not* a bug you are not supposed to run production servers with display_errors nor should you echo out traces at all ------------------------------------------------------------------------ [2018-10-04 13:22:16] edv at aulenbacher dot de Description: ------------ When printing a stacktrace of a failed attempt to connect to a database, the password passed to PDO-constructor is shown clearly. Test script: --------------- Connect via PDO to a database with a wrong password, catch that exception and do file_put_contents('php://stderr', $e); Expected result: ---------------- Password is not printed out readable. Actual result: -------------- Password is printed out readable. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76970&edit=1

« previous php.bugs (#217408) next »