-
Bug
-
Resolution: Unresolved
-
Major
-
None
-
Jenkins 1.556 envinject 1.89
The "envInjectPasswordEntry.password" input field in the job config, and also the related field in the global config, should get an autocomplete="off" attribute – else there's the real danger of leaking the Jenkins login password by browser auto-fill.
- is related to
-
JENKINS-22288 Disable username / password default values
-
- Open
-
-
JENKINS-22338 Safari silently overwrites various username or password fields
-
- Closed
-
Please explain how this can be reproduced.
In "Inject passwords to the build as environment variables", specifying a password foobar and saving, accessing the page afterwards results in 4l1OLblQ8negGA2Ldqe6HCiHhu+VGHtVSEQdPSSDna8= being entered in the password field (it's obviously much longer, and inspect element shows the value). Even when enabling password storage in my browser after saving the config page the first time (Firefox 28). Jenkins 1.532.2, env-inject 1.89.