Session credentials still stored....

Session credentials still stored....

avatar

If you setup a session with session specific credentials and then later change to credential repository it still saves the session specific credentials. Not only that but I can't clear them without going in twice to save it as session specific and then as repository again. This unnoticed behavior has led to several credentials not being cleared and thus being a security risk.

All Comments (3)

avatar

Hi,
I have entered a bug for that. Sorry about that.

David Hervieux

avatar

thank you. The batch clear credentials cleaned it up, but the credentials where at risk.

avatar

This is now fixed in our v8.0 (internal build)

David Hervieux