Unprivileged user may access plugin uninstall form

This issue is archived. You can view it, but you can't modify it. Learn more

XMLWordPrintable

    • Type: Bug
    • Resolution: Fixed
    • Priority: Minor
    • Component/s: core
    • Environment:

      Through forceful browsing, it is possible to reach the uninstall page for plugins, e.g. http://$JENKINS_URL/pluginManager/plugin/saml/uninstall

      Submitting the form results in an accessed denied exception. This form should not be reachable for normal users.

            Assignee:
            Daniel Beck
            Reporter:
            Josh Cook
            Archiver:
            Jenkins Service Account

              Created:
              Updated:
              Resolved:
              Archived: