Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-8774

CIFS-Publisher prints password in cleartext in log and settings file

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Major Major
    • cifs-plugin
    • None
    • Hudson 1.395
      CIFS-Publisher Plugin 1.1.12
      Windows XP SP3 Host

      See HUDSON-8720 for the original issue before the move to Jenkins.

      The password for the share appears in cleartext in hudson.out.log (I believe it happens when saving the system configuration) and in com.slide.hudson.plugins.CIFSPublisher.xml.

      The password should never be stored/displayed or it should be stored encrypted or as a hash.

          [JENKINS-8774] CIFS-Publisher prints password in cleartext in log and settings file

          Alex Earl added a comment -

          Removed output of URL to the log or to stdout. Added a warning in the configuration to show that the password would be stored in plain text.

          Alex Earl added a comment - Removed output of URL to the log or to stdout. Added a warning in the configuration to show that the password would be stored in plain text.

          Darth Vader added a comment -

          Tested in 1.1.13. The password does not show in the log. There is a warning that the password is in cleartext in the help.

          Darth Vader added a comment - Tested in 1.1.13. The password does not show in the log. There is a warning that the password is in cleartext in the help.

            slide_o_mix Alex Earl
            dvader Darth Vader
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved: