Hypervisor.DescriptorImpl.doFillCredentialsIdItems should have a permissions check lest it expose credentials IDs and descriptions to anonymous users. Check ssh-slaves-plugin for suggestions.

          [JENKINS-25034] Credentials metadata leak in Hypervisor

          Jesse Glick created issue -
          Jesse Glick made changes -
          Link New: This issue is blocking SECURITY-158 [ SECURITY-158 ]
          G. Kr. made changes -
          Assignee Original: Philipp Bartsch [ tastybug ] New: G. Kr. [ gkr ]
          R. Tyler Croy made changes -
          Workflow Original: JNJira [ 158934 ] New: JNJira + In-Review [ 179798 ]
          Bastian Germann made changes -
          Assignee Original: G. Kr. [ gkr ] New: Bastian Germann [ bgermann ]
          Bastian Germann made changes -
          Released As New: https://github.com/jenkinsci/libvirt-slave-plugin/commit/a14e4387f9cbddb86db1eb55985ff74502e926dc
          Resolution New: Fixed [ 1 ]
          Status Original: Open [ 1 ] New: Fixed but Unreleased [ 10203 ]
          Bastian Germann made changes -
          Status Original: Fixed but Unreleased [ 10203 ] New: Resolved [ 5 ]
          Bastian Germann made changes -
          Status Original: Resolved [ 5 ] New: Closed [ 6 ]

            bgermann Bastian Germann
            jglick Jesse Glick
            Votes:
            1 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: