Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-26845

Security: HipChat Plugin can leak global hipchat server host name and token

XMLWordPrintable

      It seems that when you save a Jenkins job with HipChat plugin installed it copies the Global configuration settings into the job XML file. Anybody who can view job configuration or job configuration history can see the sensitive HipChat server and token information. This is a security issue and also a pain to update if you need to re-save 30+ jenkins jobs.

            aldaris aldaris
            gena01 Gennady Feldman
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: