GitHub saved plaintext passwords of npm users in log files, post mortem reveals

1 year ago 51
BOOK THIS SPACE FOR AD
ARTICLE AD

27. May 2022

This article has been indexed from

The Register – Security

Unrelated to the OAuth token attack, but still troubling as org reveals details of around 100,000 users were grabbed by the baddies

GitHub has revealed it stored a “number of plaintext user credentials for the npm registry” in internal logs following the integration of the JavaScript package registry into GitHub’s logging systems.…

Read the original article:

Related

Read Entire Article