Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-16756

New users in people list after security scan

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Duplicate
    • Icon: Major Major
    • _unsorted
    • None

      After running an external security scan of our instance of Jenkins there were users in the people list that should not be there. We can recreate the issue but are unable to collect information pertinent to pointing exactly to how the users ended up in the system. We're willing to provide additional information with guidance from the project. This may be an issue of security since each of those people are assigned an API key. If there was a way to obtain the API key then the method by which the scanner was able to create the users in the people list could eventually lead to access.

            Unassigned Unassigned
            amurphyrg Adam Murphy
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: