Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-10326

Password is exposed in build metadata.

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Critical Critical
    • p4-plugin
    • None
    • Perforce Plugin 1.2.8

      I've recently discovered that the perforce plugin stores the perforce password plain text in the build.xml files used for serializing build information. This seems to be a side effect of the PerforceTagAction including the Depot object for later use during tagging, which has the password inside it. This may or may not depend upon JENKINS-2947, as that would eliminate the need for the Depot object to be stored.

            rpetti Rob Petti
            rpetti Rob Petti
            Votes:
            1 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved: