atmoz/sftp

User Names and Passwords exposed in Logs

sgu07ght opened this issue · 1 comments

Problem:
During bootup while reading users.conf from a secret / configmaps whole line gets dumped into logs that includes the credentials.

Observation/Solution:
We may need to tweak the 'log' function inside the create-sftp-user.
Planning to submit a PR on this matter.

Proof, snap:

image

vkg23 commented

PR submitted on this matter. #363