View name allows '..'

This issue is archived. You can view it, but you can't modify it. Learn more

XMLWordPrintable

      In Jenkins 1.480.2.1 it is possible to create a view called '..'. Since actions on a view include the view name in the URL, '..' being interpreted as directory traversal is an issue. As such, it is not possible to view, edit, or delete a view with this name via standard methods.

      To read more, see my post on StackOverflow.
      http://stackoverflow.com/questions/14445729/how-to-delete-a-view-named/

            Assignee:
            sogabe
            Reporter:
            Jeffrey Fairley
            Archiver:
            Jenkins Service Account

              Created:
              Updated:
              Resolved:
              Archived: