-
Bug
-
Resolution: Fixed
-
Major
-
Jenkins v2.4.18
Jira Pipeline Steps v2.0.165.v8846cf59f3db
The Jira Pipeline Steps plugin currently has two security vulnerabilities assigned to it:
These are preventing me from using this plugin in our CI/CD pipelines and it would be really nice to have these resolved as it would streamline/automate the processes we have in place by a lot!
andrewk_7 before the vulnerabilities were disclosed, the plugin maintainer was contacted by the security team and invited to resolve the issues. The maintainer chose not to resolve those vulnerabilities. Creating a new issue report that asks the maintainer to resolve the issues is unlikely to persuade the maintainer to resolve the issues.
You're more likely to persuade the maintainer by providing an implementation of the fixes for those issues. The plugin source code is https://github.com/jenkinsci/jira-steps-plugin . When the fixes are ready, you can run them yourself, confirm they work, and share them with the community as a pull request.