Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-16608

View name allows '..'

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Resolved (View Workflow)
    • Priority: Major
    • Resolution: Fixed
    • Component/s: core
    • Labels:
      None
    • Similar Issues:

      Description

      In Jenkins 1.480.2.1 it is possible to create a view called '..'. Since actions on a view include the view name in the URL, '..' being interpreted as directory traversal is an issue. As such, it is not possible to view, edit, or delete a view with this name via standard methods.

      To read more, see my post on StackOverflow.
      http://stackoverflow.com/questions/14445729/how-to-delete-a-view-named/

        Attachments

          Activity

          Hide
          scm_issue_link SCM/JIRA link daemon added a comment -

          Code changed in jenkins
          User: Seiji Sogabe
          Path:
          changelog.html
          core/src/main/java/jenkins/model/Jenkins.java
          core/src/main/resources/hudson/model/Messages.properties
          core/src/main/resources/hudson/model/Messages_ja.properties
          test/src/test/java/hudson/model/ViewTest.java
          http://jenkins-ci.org/commit/jenkins/d8b29df3558724090efaf18326937075c25ba7f3
          Log:
          [FIXED JENKINS-16608] View name should not allow "..".


          You received this message because you are subscribed to the Google Groups "Jenkins Commits" group.
          To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-commits+unsubscribe@googlegroups.com.
          For more options, visit https://groups.google.com/groups/opt_out.

          Show
          scm_issue_link SCM/JIRA link daemon added a comment - Code changed in jenkins User: Seiji Sogabe Path: changelog.html core/src/main/java/jenkins/model/Jenkins.java core/src/main/resources/hudson/model/Messages.properties core/src/main/resources/hudson/model/Messages_ja.properties test/src/test/java/hudson/model/ViewTest.java http://jenkins-ci.org/commit/jenkins/d8b29df3558724090efaf18326937075c25ba7f3 Log: [FIXED JENKINS-16608] View name should not allow "..". – You received this message because you are subscribed to the Google Groups "Jenkins Commits" group. To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-commits+unsubscribe@googlegroups.com. For more options, visit https://groups.google.com/groups/opt_out .
          Hide
          dogfood dogfood added a comment -

          Integrated in jenkins_main_trunk #2398
          [FIXED JENKINS-16608] View name should not allow "..". (Revision d8b29df3558724090efaf18326937075c25ba7f3)

          Result = SUCCESS
          Seiji Sogabe : d8b29df3558724090efaf18326937075c25ba7f3
          Files :

          • test/src/test/java/hudson/model/ViewTest.java
          • core/src/main/java/jenkins/model/Jenkins.java
          • core/src/main/resources/hudson/model/Messages_ja.properties
          • core/src/main/resources/hudson/model/Messages.properties
          • changelog.html
          Show
          dogfood dogfood added a comment - Integrated in jenkins_main_trunk #2398 [FIXED JENKINS-16608] View name should not allow "..". (Revision d8b29df3558724090efaf18326937075c25ba7f3) Result = SUCCESS Seiji Sogabe : d8b29df3558724090efaf18326937075c25ba7f3 Files : test/src/test/java/hudson/model/ViewTest.java core/src/main/java/jenkins/model/Jenkins.java core/src/main/resources/hudson/model/Messages_ja.properties core/src/main/resources/hudson/model/Messages.properties changelog.html

            People

            Assignee:
            sogabe sogabe
            Reporter:
            jfairley Jeffrey Fairley
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved: