influxdb-client-csharp icon indicating copy to clipboard operation
influxdb-client-csharp copied to clipboard

I used System Informer to check the HTTPS commands sent by influxdb-client-csharp and found that the Token, which is sensitive information, was not promptly cleared from memory.

Open Shirley-Ji-59 opened this issue 8 months ago • 1 comments

Steps to reproduce: List the minimal actions needed to reproduce the behavior.

  1. Use GetOrganizationApi.FindOrganizationsAsync() to get organization list.
  2. Use System Informer to get the application memory and found that we can read the Token information in the memory Capture1 Capture2

Expected behavior: the token sensitive information in memory is not visible.

Actual behavior: the token sensitive information in memory is visible.

Specifications:

  • InfluxDB Version: 4.14.0
  • Platform: Windows 10

Shirley-Ji-59 avatar Jun 20 '24 08:06 Shirley-Ji-59