Walter Kacynski created JENKINS-12904:
-----------------------------------------

             Summary: WAS Builder exposes username and password when using 
"system information" for the Master or Slave
                 Key: JENKINS-12904
                 URL: https://issues.jenkins-ci.org/browse/JENKINS-12904
             Project: Jenkins
          Issue Type: Bug
          Components: was-builder
            Reporter: Walter Kacynski
            Assignee: Daniel Petisme
            Priority: Critical


I'm not sure if this is a problem with the plugin on Jenkins it self.  The 
thread name of the was-builder task embeds the full command line which includes 
the username / password that was invoked.  I see this as a security exposure 
when using the Jenkins ui.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: 
https://issues.jenkins-ci.org/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

Reply via email to