Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-53287

[zephyr-for-jira-test-management] - ZephyrforJiraPlugin: Security risk when the job is misconfigured

XMLWordPrintable

      Currently Zephyr for JIRA plugin allows us to configure credentials in global configuration in Jenkins.

      If we want to push our Junit style results into JIRA, we need to enter the below details in Jenkins Job under publish test results to Zephyr as post build activities .

      JIRA URL
      Project Name
      Version
      Cycle
      Cycle Duation
      Cycle Prefix

       We are able to push the results, However other Jenkins user who is not associated to any JIRA project can use this "publish test results to Zephyr as post build activities" and push the results with the configured credentials,.This poses an risk where issues being created if published to the wrong project/if the Jenkins job is misconfigured?

       

       

       

            zeedeveloper Zephyr Developer
            mbhim Manjunath Bhimareddy
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated: