Summary
Secret initialization flow printed full root token to console logs/stdout.
Severity
Medium
Affected Files
cmdb-api/api/lib/secrets/inner.py
Recommended Remediation
Mask token by default and only print full token when explicit env switch is enabled.
Patch Branch
codex/sec-mask-root-token
Patch Commit
1be0610
Fork Branch URL
https://github.com/lhy8888/cmdb-security-fork/tree/codex/sec-mask-root-token