Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-34996

Sec-170-related: Release plugin needs to declare parameters

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Blocker Blocker
    • release-plugin
    • 1.651.2+ and Jenkins 2.3+

      Injecting arbitrary parameters is now forbidden, so the plugin should declare them to the jobs.
      See https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-05-11

      Major impacts:

      Undeclared vars are not present anymore

      Release Plugin was listed on the page: https://wiki.jenkins-ci.org/display/JENKINS/Plugins+affected+by+fix+for+SECURITY-170 and no issue was yet created for this.

          [JENKINS-34996] Sec-170-related: Release plugin needs to declare parameters

          Justin Fiore created issue -
          Antonio Muñiz made changes -
          Assignee Original: Peter Hayes [ petehayes ] New: Antonio Muñiz [ amuniz ]
          Antonio Muñiz made changes -
          Status Original: Open [ 1 ] New: In Progress [ 3 ]
          Matthew Griffin made changes -
          Priority Original: Major [ 3 ] New: Blocker [ 1 ]

          This renders this plugin entirely unusable, unfortunately. Even simple variable substitution in an Execute Shell is not possible, as the variables are now undefined.

          Matthew Griffin added a comment - This renders this plugin entirely unusable, unfortunately. Even simple variable substitution in an Execute Shell is not possible, as the variables are now undefined.

          I think this merits an advisory in the documentation, "Jenkins 2.3+ requires GHPRB plugin version X.Y.Z or later"

          Johnny Shields added a comment - I think this merits an advisory in the documentation, "Jenkins 2.3+ requires GHPRB plugin version X.Y.Z or later"

          Plugin is currently useless. Can't even do basic variable substitution in shell.

          Michael Templeton added a comment - Plugin is currently useless. Can't even do basic variable substitution in shell.
          Antonio Muñiz made changes -
          Remote Link New: This issue links to "PR (Web Link)" [ 14363 ]

          Antonio Muñiz added a comment - Proposed fix: https://github.com/jenkinsci/release-plugin/pull/17
          Oleg Nenashev made changes -
          Link New: This issue is related to JENKINS-35257 [ JENKINS-35257 ]

            amuniz Antonio Muñiz
            jmf10024 Justin Fiore
            Votes:
            7 Vote for this issue
            Watchers:
            14 Start watching this issue

              Created:
              Updated:
              Resolved: