Skip to content

GitLab

  • Projects
  • Groups
  • Snippets
  • Help
    • Loading...
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
gtk
gtk
  • Project overview
    • Project overview
    • Details
    • Activity
    • Releases
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 1,152
    • Issues 1,152
    • List
    • Boards
    • Labels
    • Service Desk
    • Milestones
  • Merge Requests 145
    • Merge Requests 145
  • CI / CD
    • CI / CD
    • Pipelines
    • Jobs
    • Schedules
  • Operations
    • Operations
    • Incidents
    • Environments
  • Packages & Registries
    • Packages & Registries
    • Container Registry
  • Analytics
    • Analytics
    • CI / CD
    • Repository
    • Value Stream
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Members
    • Members
  • Collapse sidebar
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
  • GNOME
  • gtkgtk
  • Issues
  • #1832

Closed
Open
Opened Feb 03, 2019 by Mateus@seanlilmateus

Safety concern: Sidebar exposes username, server and port

Use cases

I was giving a talk in an Conference, where my displayed was visible for multiple persons, due to the Sidebar and NextCloud integration everyone was able to see my NextCloud ((e.g: thomas@example.com:5555)) server address, username and on which port it is running, after a while of course some people tried to get in. This applies to any Network connected Location.

Desired behavior

The user should be able to create a Label/Alias for the any server whenever he connects to it. Specially in the case of the NextCloud integration.

Benefits of the solution

By disclosing the username and servername, an attacker just have to brute-force the password. In case of NextCloud can be a desired target, due to the amount of personal Data.

Edited Apr 16, 2019 by António Fernandes
Assignee
Assign to
None
Milestone
None
Assign milestone
Time tracking
None
Due date
None
Reference: GNOME/gtk#1832