-
Bug
-
Resolution: Fixed
-
Blocker
-
RHEL6
Job import plugin has the "Passwor/API key" in cleartext. Contents of this field are stored on the server so anyone can see the password of the user that previously imported jobs via the plugin.
I understand that API keys are preferred to be in cleartext. So ideal solution may be to split this into two separate fields: Password that will be a real password field (with obscured input) and API key that will show the key in cleartext.
- is duplicated by
-
JENKINS-33307 Password not Masked when Importing from Secured Jenkins Instance
-
- Resolved
-
- links to
[JENKINS-22942] Job Import Plugin: Password field is cleartext
Priority | Original: Minor [ 4 ] | New: Blocker [ 1 ] |
Labels | New: security |
Assignee | New: Emilio Escobar [ escoem ] |
Status | Original: Open [ 1 ] | New: In Progress [ 3 ] |
Link |
New:
This issue is duplicated by |
Remote Link | New: This issue links to "PR (Web Link)" [ 14145 ] |
Remote Link | New: This issue links to "PR (Web Link)" [ 14146 ] |
Resolution | New: Fixed [ 1 ] | |
Status | Original: In Progress [ 3 ] | New: Resolved [ 5 ] |
Workflow | Original: JNJira [ 155089 ] | New: JNJira + In-Review [ 195132 ] |