Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-26831

Mantis password written in plain text in build.xml

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Major Major
    • mantis-plugin
    • Jenkins 1.580.2
      mantis-plugin 0.25

      After a build which required an interaction with Mantis, one can found the credentials used by mantis-plugin in the file build.xml

          <hudson.plugins.mantis.MantisRegisterAction plugin="mantis@0.25">
            <site>
              <url>http://someserver/mantis/</url>
              <version>V120</version>
              <userName>aaaaa</userName>
              <password>xxxxx</password>
            </site>
            <issueNo>3465</issueNo>
          </hudson.plugins.mantis.MantisRegisterAction>
      

          [JENKINS-26831] Mantis password written in plain text in build.xml

          Code changed in jenkins
          User: Seiji Sogabe
          Path:
          src/main/java/hudson/plugins/mantis/MantisSite.java
          src/main/java/hudson/plugins/mantis/soap/mantis110/MantisSessionImpl.java
          src/main/java/hudson/plugins/mantis/soap/mantis120/MantisSessionImpl.java
          src/main/resources/hudson/plugins/mantis/MantisProjectProperty/global.jelly
          src/test/java/hudson/plugins/mantis/MantisProjectPropertyConfigSubmitTest.java
          src/test/java/hudson/plugins/mantis/MantisSiteTest.java
          http://jenkins-ci.org/commit/mantis-plugin/5cbc6c75d2da51d77b688c416b32a7f54fd88029
          Log:
          [FIXED JENKINS-26831] save secret password

          SCM/JIRA link daemon added a comment - Code changed in jenkins User: Seiji Sogabe Path: src/main/java/hudson/plugins/mantis/MantisSite.java src/main/java/hudson/plugins/mantis/soap/mantis110/MantisSessionImpl.java src/main/java/hudson/plugins/mantis/soap/mantis120/MantisSessionImpl.java src/main/resources/hudson/plugins/mantis/MantisProjectProperty/global.jelly src/test/java/hudson/plugins/mantis/MantisProjectPropertyConfigSubmitTest.java src/test/java/hudson/plugins/mantis/MantisSiteTest.java http://jenkins-ci.org/commit/mantis-plugin/5cbc6c75d2da51d77b688c416b32a7f54fd88029 Log: [FIXED JENKINS-26831] save secret password

            sogabe sogabe
            benoitandrieu Benoit Andrieu
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: