Tool downloads are vulnerable to tampering

This issue is archived. You can view it, but you can't modify it. Learn more

XMLWordPrintable

      List of references to external tools on update site are neither signed or hashed. This makes tools installer vulnerable to tampering. First content should be signed to prevent malicious third parties from modifying it and redirecting jenkins to download from unknown sources. Contents of urls should also be hashed to prevent malicious modifications at download source.

            Assignee:
            Unassigned
            Reporter:
            Sami Korhonen
            Archiver:
            Jenkins Service Account

              Created:
              Updated:
              Archived: