Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-33978

secret data is written to a file before it is secured.

      not a security issue yet as it is only in a beta and the window of opportunity is really really really small

      but the setup wizard writes an admin password to a file before it sets appropriate permissions on the file.

          [JENKINS-33978] secret data is written to a file before it is secured.

          James Nord created issue -
          James Nord made changes -
          Assignee New: James Nord [ teilo ]
          James Nord made changes -
          Status Original: Open [ 1 ] New: In Progress [ 3 ]
          James Nord made changes -
          Remote Link New: This issue links to "PR 2203 (Web Link)" [ 14148 ]
          Daniel Beck made changes -
          Labels Original: 2.0 2.0-beta New: 2.0 2.0-beta 2.0-planned

          Code changed in jenkins
          User: Daniel Beck
          Path:
          core/src/main/java/jenkins/install/SetupWizard.java
          http://jenkins-ci.org/commit/jenkins/964e967ad98fbd5040ab75ff98f0cc8238bbd09a
          Log:
          Merge pull request #2203 from jenkinsci/jtnord-patch-1

          [FIX JENKINS-33978] Set file permissions on the file before writing the secret

          Compare: https://github.com/jenkinsci/jenkins/compare/37c00cf2aff0...964e967ad98f

          SCM/JIRA link daemon added a comment - Code changed in jenkins User: Daniel Beck Path: core/src/main/java/jenkins/install/SetupWizard.java http://jenkins-ci.org/commit/jenkins/964e967ad98fbd5040ab75ff98f0cc8238bbd09a Log: Merge pull request #2203 from jenkinsci/jtnord-patch-1 [FIX JENKINS-33978] Set file permissions on the file before writing the secret Compare: https://github.com/jenkinsci/jenkins/compare/37c00cf2aff0...964e967ad98f
          SCM/JIRA link daemon made changes -
          Resolution New: Fixed [ 1 ]
          Status Original: In Progress [ 3 ] New: Resolved [ 5 ]
          R. Tyler Croy made changes -
          Workflow Original: JNJira [ 169989 ] New: JNJira + In-Review [ 198755 ]
          James Nord made changes -
          Assignee Original: James Nord [ teilo ]

            Unassigned Unassigned
            teilo James Nord
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: