-
Notifications
You must be signed in to change notification settings - Fork 249
Open
Description
Listen guys, I know it's probably just an oversight, but I nearly choked when I realized my sessions were being screen recorded by yandex metrica.
Every password I type, all the information I enter gets sent to yandex. I thought it might just be the SNAPSHOT release that is infected, but even in the 1.0.1.RELEASE and 1.2.0.RC1 jar this is still going on.
This is seriously uncool. Especially for an admin frontend that deals with potentially sensible user data.
The offending script is located in the footer-section.jsp
Metadata
Metadata
Assignees
Labels
No labels