FileCodeBox
FileCodeBox copied to clipboard
Potential Information Leakage
Describe the bug
In the settings' __init__
function, it stores sensitive data including onedrive password, AWS key into a plaintext env file which is a potential security issue described in CWE-312.
To Reproduce Steps to reproduce the behavior: Run the settings function.
Expected behavior The password should stay in the memory or change the env file permission to only available to the user running the service.
thank you,I will update it
File storage deleted