• Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Critical Critical
    • other
    • None
    • Platform: All, OS: All

      When security is enabled unauthenticated user can view system log when pointing
      the browser to "/log".

      Not in my case but that could lead to revealing sensitive information.

          [JENKINS-716] system log not secured

          akostadinov created issue -

          Fixed in 1.128.

          Kohsuke Kawaguchi added a comment - Fixed in 1.128.
          Kohsuke Kawaguchi made changes -
          Resolution New: Fixed [ 1 ]
          Status Original: Open [ 1 ] New: Resolved [ 5 ]
          Andrew Bayer made changes -
          Status Original: Resolved [ 5 ] New: Closed [ 6 ]
          R. Tyler Croy made changes -
          Workflow Original: JNJira [ 130789 ] New: JNJira + In-Review [ 200117 ]

            kohsuke Kohsuke Kawaguchi
            akostadinov akostadinov
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved: