Slack plugin reveals integration token

This issue is archived. You can view it, but you can't modify it. Learn more

XMLWordPrintable

      The Slack plugin reveals the integration token in the global configuration. In environments when many people have access to view the global configuration, this presents a security vulnerability since the token appears to give access to quite a bit of the Slack instance (though it's not entirely clear where that's configured).

            Assignee:
            Kurt Madel
            Reporter:
            Dominic Hargreaves
            Archiver:
            Jenkins Service Account

              Created:
              Updated:
              Resolved:
              Archived: