Bug - LDAP-Password is exposed in URL/Logfiles

Hi,
when testing the LDAP-Connector the user-credentials of the bind-user are send to the eramba-Server in a GET-Request.
So the credentials get logged in logfiles/proxy-log, etc.

The log entries will look like this:

GET /ldapConnectors/testLdap/time:15…?_method=PUT&data%5B_Token%5D%5Bkey%5D=d40…f06&data%5BLdapConnector%5D%5Bid%5D=1&data%5BLdapConnector%5D%5Bname%5D=LDAP±+Authenticator&data%5BLdapConnector%5D%5Bdescription%5D=&data%5BLdapConnector%5D%5Bstatus%5D=1&data%5BLdapConnector%5D%5Bhost%5D=ldaps%3A%2F%2FSRVER&data%5BLdapConnector%5D%5Bdomain%5D=XXX.de&data%5BLdapConnector%5D%5Bport%5D=636&data%5BLdapConnector%5D%5Bldap_bind_dn%5D=CN%3DUSERNAME%2CCN%3DMXXXXX%2CDC%3DXXXXX%2CDC%3Dnet&data%5BLdapConnector%5D%5Bldap_bind_pw%5D=PASSWORD&data%5BLdapConnector%5D%5Bldap_base_dn%5D=OU%3DXXXX%2CDC%3DXXXX%2CDC%3Dnet&data%5BLdapConnector%5D%5Btype%5D=authenticator&data%5BLdapConnector%5D%5Bldap_auth_filter%5D=(%26(objectCategory%3Dperson)(objectClass%3Duser)(!(userAccountControl%3A1.2.840.113556.1.4.803%3A%3D2))(sAMAccountName%3D%25USERNAME%25))&data%5BLdapConnector%5D%5B_ldap_auth_filter_username_value%5D=YYYYY&data%5BLdapConnector%5D%5Bldap_auth_attribute%5D=sAMAccountName&data%5BLdapConnector%5D%5Bldap_name_attribute%5D=displayName&data%5BLdapConnector%5D%5Bldap_email_attribute%5D=mail&data%5BLdapConnector%5D%5Bldap_memberof_attribute%5D=memberOf&data%5BLdapConnector%5D%5Bldap_grouplist_filter%5D=&data%5BLdapConnector%5D%5Bldap_grouplist_name%5D=&data%5BLdapConnector%5D%5Bldap_groupmemberlist_filter%5D=&data%5BLdapConnector%5D%5Bldap_group_account_attribute%5D=&data%5BLdapConnector%5D%5Bldap_group_email_attribute%5D=&data%5BLdapConnector%5D%5Bldap_group_fetch_email_type%5D=email-attribute&data%5BLdapConnector%5D%5Bldap_group_mail_domain%5D=&data%5B_Token%5D%5Bfields%5D=fa…63f%253ALdapConnector._ldap_auth_filter_username_value%257CLdapConnector.id&data%5B_Token%5D%5Bunlocked%5D= HTTP/1.1

That log is a requets eramba made to itself, right? (you are not included the header of the HTTP request).

Can you confirm?

Yes,
it shows up in the Apache httpd-log (and in the log of an proxy-server in front of it).
It is triggered by this page when you test the ldap-settings: “https://[host]/ldapConnectors/edit/1”