Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-13706

Jabber/IRCBot credentials stored in clear text

    XMLWordPrintable

    Details

    • Similar Issues:

      Description

      If you open hudson.plugins.jabber.im.transport.JabberPublisher.xml you will notice that the jabber password is stored in cleartext :

       
      
        <hudson.plugins.jabber.im.transport.JabberPublisherDescriptor>
        [...]
       	<hudsonPassword>Protext_the_innocent</hudsonPassword> 
      

      Other components (ldap bind password, svn) have a hash mechanism as far as I can see, not sure if there is a common library to use but it would be a nice addition.

      Thank you !

        Attachments

          Activity

          jnrg Julien R. created issue -
          kutzi kutzi made changes -
          Field Original Value New Value
          Component/s ircbot [ 15550 ]
          Summary Config stored jabber credential in clear text Jabber/IRCBot credentials stored in clear text
          Hide
          scm_issue_link SCM/JIRA link daemon added a comment -

          Code changed in jenkins
          User: Christoph Kutzinski
          Path:
          pom.xml
          src/main/java/hudson/plugins/ircbot/IrcPublisher.java
          http://jenkins-ci.org/commit/ircbot-plugin/cbe23a16db65a2e857ff5f5404a37b61192ffbc2
          Log:
          Save passwords scrambled JENKINS-13706

          Show
          scm_issue_link SCM/JIRA link daemon added a comment - Code changed in jenkins User: Christoph Kutzinski Path: pom.xml src/main/java/hudson/plugins/ircbot/IrcPublisher.java http://jenkins-ci.org/commit/ircbot-plugin/cbe23a16db65a2e857ff5f5404a37b61192ffbc2 Log: Save passwords scrambled JENKINS-13706
          Hide
          scm_issue_link SCM/JIRA link daemon added a comment -

          Code changed in jenkins
          User: Christoph Kutzinski
          Path:
          pom.xml
          src/main/java/hudson/plugins/jabber/im/transport/JabberPublisherDescriptor.java
          http://jenkins-ci.org/commit/jabber-plugin/d1515ae837d00be74e97882e10dfcbd6077f1b83
          Log:
          Save password scrambled JENKINS-13706

          Show
          scm_issue_link SCM/JIRA link daemon added a comment - Code changed in jenkins User: Christoph Kutzinski Path: pom.xml src/main/java/hudson/plugins/jabber/im/transport/JabberPublisherDescriptor.java http://jenkins-ci.org/commit/jabber-plugin/d1515ae837d00be74e97882e10dfcbd6077f1b83 Log: Save password scrambled JENKINS-13706
          kutzi kutzi made changes -
          Resolution Fixed [ 1 ]
          Status Open [ 1 ] Resolved [ 5 ]
          rtyler R. Tyler Croy made changes -
          Workflow JNJira [ 144173 ] JNJira + In-Review [ 190948 ]

            People

            Assignee:
            kutzi kutzi
            Reporter:
            jnrg Julien R.
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved: