Skip to content

AD user password hashes are stored in Gitea database #14065

Open
@songmeo

Description

@songmeo
  • Gitea version: 1.12.6
  • Database
    • MySQL

Description

We are using LDAP Active Directory for Gitea authentication. Recently, we noticed AD users password hashes are stored in Gitea database. This shouldn't be the best practice since we already have LDAP.

Metadata

Metadata

Assignees

No one assigned

    Labels

    topic/authenticationtopic/securitySomething leaks user information or is otherwise vulnerable. Should be fixed!

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions