-
Bug
-
Resolution: Fixed
-
Major
not a security issue yet as it is only in a beta and the window of opportunity is really really really small
but the setup wizard writes an admin password to a file before it sets appropriate permissions on the file.
- links to
[JENKINS-33978] secret data is written to a file before it is secured.
Assignee | New: James Nord [ teilo ] |
Status | Original: Open [ 1 ] | New: In Progress [ 3 ] |
Remote Link | New: This issue links to "PR 2203 (Web Link)" [ 14148 ] |
Labels | Original: 2.0 2.0-beta | New: 2.0 2.0-beta 2.0-planned |
Resolution | New: Fixed [ 1 ] | |
Status | Original: In Progress [ 3 ] | New: Resolved [ 5 ] |
Workflow | Original: JNJira [ 169989 ] | New: JNJira + In-Review [ 198755 ] |
Assignee | Original: James Nord [ teilo ] |
Code changed in jenkins
User: Daniel Beck
Path:
core/src/main/java/jenkins/install/SetupWizard.java
http://jenkins-ci.org/commit/jenkins/964e967ad98fbd5040ab75ff98f0cc8238bbd09a
Log:
Merge pull request #2203 from jenkinsci/jtnord-patch-1
[FIX JENKINS-33978] Set file permissions on the file before writing the secret
Compare: https://github.com/jenkinsci/jenkins/compare/37c00cf2aff0...964e967ad98f