-
Improvement
-
Resolution: Not A Defect
-
Major
-
Groovy Version: 2.4.12 JVM: 1.8.0_152 Vendor: Oracle Corporation OS: Mac OS X
Jenkins 2.73.2
Submitter option can be modified in the replay pipeline.
Since submitter contains user IDs and/or external group names of person or people permitted to respond to the input, unauthorized folks can overwrite the pipeline functionality by using the replay feature.
[JENKINS-47661] Preserve submitter in input step while replay pipeline.
Component/s | New: pipeline-input-step-plugin [ 21708 ] | |
Component/s | Original: pipeline [ 21692 ] |
Labels | Original: pipeline, security | New: security |
Resolution | New: Not A Defect [ 7 ] | |
Status | Original: Open [ 1 ] | New: Resolved [ 5 ] |