Central configuration of repository user tear open a serious security leak

This issue is archived. You can view it, but you can't modify it. Learn more

XMLWordPrintable

      Everybody who has job configuration access rights (a so called job configurator) can select any subversion repository user configured centrally in jenkins. In past versions the job configurator must knew the user and password combination of the used subversion repository. Now it is possible that the job configurator can configure a subversion repository without having access rights but only knowing the URL and the user login but not knowing the password. So the job configurator can bypass subversion repository access restrictions to gain access to that repository content.

      We have about 200 jobs configured and using project specific authorization. Lots of jobs have active NDAs. So this is a serious security issue for us.

            Assignee:
            Unassigned
            Reporter:
            Steffen Mork
            Archiver:
            Jenkins Service Account

              Created:
              Updated:
              Archived: