BasicSSHUserPrivateKey.DirectEntryPrivateKeySource.privateKey stored in plaintext

This issue is archived. You can view it, but you can't modify it. Learn more

XMLWordPrintable

      The credentials.xml file holds a plaintext copy of the credentials stored via Jenkins. On a fresh install of Jenkins, this file has world readable permissions by default:

      $ ls -l /var/lib/jenkins/credentials.xml
      rw-rr- 1 jenkins jenkins 2863 Feb 12 19:00 /var/lib/jenkins/credentials.xml

      It should have at least group readable permissions only.

            Assignee:
            Stephen Connolly
            Reporter:
            William Hutson
            Archiver:
            Jenkins Service Account

              Created:
              Updated:
              Resolved:
              Archived: