Sec-170-related: Release plugin needs to declare parameters

This issue is archived. You can view it, but you can't modify it. Learn more

XMLWordPrintable

      Injecting arbitrary parameters is now forbidden, so the plugin should declare them to the jobs.
      See https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-05-11

      Major impacts:

      Undeclared vars are not present anymore

      Release Plugin was listed on the page: https://wiki.jenkins-ci.org/display/JENKINS/Plugins+affected+by+fix+for+SECURITY-170 and no issue was yet created for this.

            Assignee:
            Antonio Muñiz
            Reporter:
            Justin Fiore
            Archiver:
            Jenkins Service Account

              Created:
              Updated:
              Resolved:
              Archived: