• Icon: Bug Bug
    • Resolution: Not A Defect
    • Icon: Major Major
    • None
    • Jenkins 2.149 - Credential Binding 1.17

      It looks like saving password variable from withCredentials using writeFile doesn't mask the password. I consider this to be a security vulnerability.

          [JENKINS-54538] Ability to save unmasked credentials to file

          https://jenkins.io/doc/pipeline/steps/credentials-binding/ says this is by design: "The masking could of course be trivially circumvented; anyone permitted to configure a job or define Pipeline steps is assumed to be trusted to use any credentials in scope however they like."

          Kalle Niemitalo added a comment - https://jenkins.io/doc/pipeline/steps/credentials-binding/ says this is by design: "The masking could of course be trivially circumvented; anyone permitted to configure a job or define Pipeline steps is assumed to be trusted to use any credentials in scope however they like."

          Make sens, can't believe I missed the obvious

          Tomasz Fijarczyk added a comment - Make sens, can't believe I missed the obvious

            Unassigned Unassigned
            t0mmili Tomasz Fijarczyk
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: