Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-478

anonymous user should not be able to tag sources

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed (View Workflow)
    • Priority: Major
    • Resolution: Fixed
    • Component/s: core
    • Labels:
      None
    • Environment:
      Platform: All, OS: All
    • Similar Issues:

      Description

      On a site with security enabled: I'm not logged in as a user, but I can see the
      page "tag this build". (I did not try it on the mentioned site.) Even if this
      doesn't work, I should never see this page.

        Attachments

          Activity

          Hide
          kohsuke Kohsuke Kawaguchi added a comment -

          Fixed in 1.103.

          This was not just an UI issue but actually also a security issue. It allowed
          anyone to tag the workspace.

          Show
          kohsuke Kohsuke Kawaguchi added a comment - Fixed in 1.103. This was not just an UI issue but actually also a security issue. It allowed anyone to tag the workspace.

            People

            Assignee:
            Unassigned Unassigned
            Reporter:
            gradopado gradopado
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved: