Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-40017

Passwords are replaced but not masked in global envs

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Blocker Blocker
    • mask-passwords-plugin
    • Jenkins ver. 2.19.3
      Mask Passwords Plugin 2.8

      We have a global password called JENKINSPASS

      We have a global env ANT_OPTS defined, which references it like -Djavax.net.ssl.keyStorePassword=${JENKINSPASS}

      For no apparent reason (we didn't upgrade) an unmasked value of the password started to appear in "Enviorment Variables" view. Note JENKINSPASS itself is masked.

      ANT_OPTS	-Djavax.net.ssl.keyStorePassword=N0wC0mpr0miss3dS3cr3t
      JENKINSPASS	[*******]
      

      Older builds don't contain an entry for ANT_OPTS at all.

            Unassigned Unassigned
            jbochenski Jakub Bochenski
            Votes:
            1 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated: