• 2.171

      From https://twitter.com/scy/status/1112663270341644289 it looks like Jenkins setup wizard does not properly escape some form fields and processes them as code ( ? ).

          [JENKINS-56856] Setup wizards handles password field wrong

          Daniel Beck created issue -
          Gavin Mogan made changes -
          Assignee New: Gavin Mogan [ halkeye ]

          Gavin Mogan added a comment -

          Did some quick investigation and found out that while all the other fields were escaped, the large json blob was not, so jetty didn't know how to handled the non escaped data.

          Gavin Mogan added a comment - Did some quick investigation and found out that while all the other fields were escaped, the large json blob was not, so jetty didn't know how to handled the non escaped data.

          Gavin Mogan added a comment -

          Gavin Mogan added a comment - https://github.com/jenkinsci/jenkins/pull/3960
          Gavin Mogan made changes -
          Status Original: Open [ 1 ] New: In Progress [ 3 ]
          Daniel Beck made changes -
          Labels Original: setup-wizard New: lts-candidate setup-wizard
          Daniel Beck made changes -
          Released As New: 2.171
          Resolution New: Fixed [ 1 ]
          Status Original: In Progress [ 3 ] New: Resolved [ 5 ]
          Daniel Beck made changes -
          Link New: This issue is duplicated by JENKINS-53733 [ JENKINS-53733 ]
          Oliver Gondža made changes -
          Labels Original: lts-candidate setup-wizard New: 2.164.3-fixed setup-wizard

            halkeye Gavin Mogan
            danielbeck Daniel Beck
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: