Missing User Warnings
Medium
- Confidence
- 95% confidence
- Finding
- The guide recommends exporting the master password into an environment variable for unattended use without warning that environment variables may be exposed through process listings, debug dumps, CI logs, shell history, or inherited subprocess environments. Because this password unlocks the encrypted credential store, compromise of the variable can expose all managed database secrets for the tool.
