ID: 13722
Title: Don't return passwords
Component: REST API
Level: 1
Class: Security fix
Version: 2.1.0i1
Before this werk it was possible to retrieve stored passwords in cleartext over
the <i>REST API</i>. They are not shown in the GUI and should not be revealed
to a user.
A Checkmk admin can still retrieve the password with access to the filesystem
though.
Show replies by date