Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-23447

Sensitive build variables recorded in EnvInjectSavable and displayed in EnvInjectAction

      If you have a BuildWrapper which overrides makeSensitiveBuildVariables to specify that its additions are to be considered secret, then add an EnvInjectBuilder which adds some unrelated variables, injectedEnvVars.txt includes the sensitive variables (in plaintext) and /job/.../.../injectedEnvVars/ shows them as well.

          [JENKINS-23447] Sensitive build variables recorded in EnvInjectSavable and displayed in EnvInjectAction

          Jesse Glick created issue -
          Jesse Glick made changes -
          Link New: This issue is blocking JENKINS-23630 [ JENKINS-23630 ]
          Jesse Glick made changes -
          Link New: This issue is related to JENKINS-24287 [ JENKINS-24287 ]
          Jesse Glick made changes -
          Link New: This issue is related to JENKINS-4428 [ JENKINS-4428 ]
          Steven Christou made changes -
          Assignee Original: Gregory Boissinot [ gbois ] New: Nicolas De Loof [ ndeloof ]
          Resolution New: Fixed [ 1 ]
          Status Original: Open [ 1 ] New: Resolved [ 5 ]
          Oleg Nenashev made changes -
          Link New: This issue is related to JENKINS-27363 [ JENKINS-27363 ]
          Oleg Nenashev made changes -
          Link Original: This issue is related to JENKINS-27363 [ JENKINS-27363 ]
          Jesse Glick made changes -
          Link New: This issue is related to JENKINS-12423 [ JENKINS-12423 ]
          R. Tyler Croy made changes -
          Workflow Original: JNJira [ 156075 ] New: JNJira + In-Review [ 195334 ]

            ndeloof Nicolas De Loof
            jglick Jesse Glick
            Votes:
            1 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated:
              Resolved: