v0.8.8 is out and addresses a security issue

2 views
Skip to first unread message

Maxime Beauchemin

unread,
Apr 15, 2016, 12:54:42 AM4/15/16
to airbnb_caravel
Caravel enthusiasts,

A quick note to say that 0.8.8 was just released and fixes a potentially important security issue where database passwords might have been exposed through the "show" view on the database model. Thanks to @lenguyenthedat  for pointing this out here.

Depending on what/who/when has had access to Caravel in your organization, you may want to rotate your database(s) password. The passwords are encrypted in the metadata database but may have been visible through this page depending on users roles/permissions.

Sorry for the inconvenience, 

Max
Reply all
Reply to author
Forward
0 new messages