-
Notifications
You must be signed in to change notification settings - Fork 57
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ODS 2.x - Nexus password in plain text at the $JenkinsLog on a quickstarter build #288
Comments
This is fixed in master via #211. Ok to close? Or should we back port to 2.x? |
this only happens ins debug mode -or? |
@clemensutschig In master yes, in 2.x also in info mode. |
This need to be ported to 2.x, is a huge security issue |
not fixed on master (if in debug mode) - context.toString |
@michaelsauter I assume because the title is ODS 2.x, that yes, it needs to be ported to 2.x.
|
OK. Let's backport this for 2.x. @renedupont Can you help there? I guess applying/testing what you did on master back then should work. I can make sure this is fixed on master as I'm doing testing there anyway. |
@michaelsauter as @clemensutschig commented this is not fixed if logging level is set to |
@martsec fyi! |
ODS 2.x - Security bug. A password in plain text during the execution of a Jenkins quickstarter build. (all quickstarters builds the password).
Log output here...
The text was updated successfully, but these errors were encountered: