Kodi Community Forum

Full Version: Credential exposure
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
1. Edit existing smb entry
2. Fill in invalid hostname (maybe invalid share)
3. See plain password from the UI

Image
The reproduction misses step 4 - try to enter the wrongly added source - after wards it will expose the credentials...
sorry i don't know what you mean. by "enter the source". in my case it exposed the credentials right after i clicked okay in step 2, or is it the "click okay" you are missing?
Thx for the report - fix is proposed for inclusion here:

https://github.com/xbmc/xbmc/pull/8768

I needed to try to enter the newly edited source before the disclosure happend (after clicking away the following timeout dialog). Might be small platform differences ..
Ha. That's a bug I had for long time but never figured out how I actually triggered it.
And its there since 2009 or even earlier (allthekillers move linux port to trunk commit at least)