[Pkg-nagios-devel] Bug#288620: nagios-common: nagios CGI reveal potentially sensitive information

Jerome Alet Jerome Alet <alet@librelogiciel.com>, 288620@bugs.debian.org
Tue, 4 Jan 2005 22:38:13 +0100


On Tue, Jan 04, 2005 at 09:40:28PM +0100, Martin Zobel-Helas wrote:
> 
> On Tuesday, 04 Jan 2005, you wrote:

> > by clicking on "Process Info" in the Nagios CGI, at 
> > the bottom of the page appears the complete connection string to 
> > the database (I use PostgreSQL, but the problem is certainely the 
> > same with MySQL).
> 
> I am using nagios-mysql 2:1.3-0+pre6 and i dont have this problem.

Found !

It was my bad, you can safely close this bug.

In fact I had modified check_nagios_db to output these variables (I 
removed the commented 'print') when I was setting it up, in case 
something would went wrong, and I didn't realize that what I saw 
was the first line of the output of this command.

Once I had re-commented out the 'print' line, all was OK.

Sorry for this guys, and thanks for your help.

Jerome Alet