Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-16632

Jclouds BlobStore writes key to console log when blob store returns 401 error.

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Major Major
    • jclouds-plugin
    • None

      The Jclouds jenkins plugin can expose your Jclouds Storage credentials if the remote store returns a 401 not authorized. When this happens an exception is thrown which is written to the build's console log and this exception contains the sensitive data. This exception should be caught and handled in a way that does not expose this information in build logs (or any logs ideally).

            Unassigned Unassigned
            cboylan Clark Boylan
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: