Details
-
Type:
Bug
-
Status: Resolved (View Workflow)
-
Priority:
Critical
-
Resolution: Not A Defect
-
Component/s: build-user-vars-plugin, naginator-plugin
-
Labels:None
-
Similar Issues:
Description
When pressing Re-try after failed build, Naginator plugin is using user credentials of previous failed build. Username can belong to another user. This feature makes it possible to bypass the user authorization rules. Could this plug-in feature to change? It would be better to use current user (who is pressing Re-try button) credentials in Re-try feature by default (for example having global config checkbox settings for this).
I want to know what credentials you exactly mean (credentials plugin?)
Would you tell me some scenarios that can cause security issues?