Uploaded image for project: 'Nuxeo Studio'
  1. Nuxeo Studio
  2. NXS-5457

NOS: prevent default credentials usage

    XMLWordPrintable

    Details

    • Type: Epic
    • Status: Resolved
    • Priority: Major
    • Resolution: Done
    • Affects Version/s: None
    • Fix Version/s: 3.20.0
    • Component/s: Roles & Permissions

      Description

      When creating users and groups in Studio, the Administrator user with its default password is added automatically.

      If customers keep it as is and use the override policy, it means the instance will drop every existing user and use the Studio config instead at restart, with the default credentials.

      We noticed recently a big number of important customers in our cloud using the default credentials, probably without knowing it. We need to prevent our customers from putting their security at risk.

        Attachments

          Activity

            People

            • Assignee:
              Unassigned
              Reporter:
              bchauvin Bertrand Chauvin
              Participants:
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved: