-
Bug
-
Resolution: Not A Defect
-
Blocker
-
None
I'm currently using the credentials plugin to encrypt may username and password . However, in my pipeline script I found a way to hack the password by inserting a character in the password this causes the password to be printed clearly and since I'm the person who added the character if I removed it then I have the password.
This causes a huge security issue for us.
- duplicates
-
JENKINS-50242 withCredentials step masking easily bypassed
- Resolved
- relates to
-
JENKINS-42950 credentials-binding-plugin not masking secret text when it includes a single quote
- Resolved