Summary
Plaintext passwords are being stored in access logs.
Fixed versions
This has been patched in versions 4.1.6 and 4.2.3. Centers may need to apply a FACL for staff users to continue to view the files in these directories. Centers can apply this command setfacl -m g:groupname:rx /var/log/ondemand-nginx where "groupname" needs to be replaced with the actual group to give certain groups access.
Summary
Plaintext passwords are being stored in access logs.
Fixed versions
This has been patched in versions 4.1.6 and 4.2.3. Centers may need to apply a FACL for staff users to continue to view the files in these directories. Centers can apply this command
setfacl -m g:groupname:rx /var/log/ondemand-nginxwhere "groupname" needs to be replaced with the actual group to give certain groups access.