Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-19830

Masked Password visible as plain text in Msbuild Plugin

    XMLWordPrintable

    Details

    • Similar Issues:

      Description

            • VERY CRITICAL *****

      Masked Password Clearly visible.

      When Pass build variables as properties is marked as true. Global password will be clearly visible in console output. It was found in version 1.20, it was not in version 1.16.

      Please Fix this issue as soon as possible, as it is a security threat for us.

      For reference attaching image. in which global declared password visible clearly with msbuild command.

      but not visible when i echo in windows batch command.

        Attachments

          Issue Links

            Activity

            Hide
            jglick Jesse Glick added a comment -

            Filed pull #10.

            Show
            jglick Jesse Glick added a comment - Filed pull #10.
            Hide
            scm_issue_link SCM/JIRA link daemon added a comment -

            Code changed in jenkins
            User: Jesse Glick
            Path:
            src/main/resources/hudson/plugins/msbuild/MsBuildBuilder/config.jelly
            src/main/webapp/help-BuildVariablesAsProperties.html
            http://jenkins-ci.org/commit/msbuild-plugin/b37dba21830d9343b4d619904ad687428111feb7
            Log:
            JENKINS-19830 Warn about passwords in log.

            Show
            scm_issue_link SCM/JIRA link daemon added a comment - Code changed in jenkins User: Jesse Glick Path: src/main/resources/hudson/plugins/msbuild/MsBuildBuilder/config.jelly src/main/webapp/help-BuildVariablesAsProperties.html http://jenkins-ci.org/commit/msbuild-plugin/b37dba21830d9343b4d619904ad687428111feb7 Log: JENKINS-19830 Warn about passwords in log.
            Hide
            scm_issue_link SCM/JIRA link daemon added a comment -

            Code changed in jenkins
            User: Gregory Boissinot
            Path:
            src/main/resources/hudson/plugins/msbuild/MsBuildBuilder/config.jelly
            src/main/webapp/help-BuildVariablesAsProperties.html
            http://jenkins-ci.org/commit/msbuild-plugin/f30df9df32575d31af3211e8f79f5cbea48c69b6
            Log:
            Merge pull request #10 from jglick/mask-args-JENKINS-19830

            [FIXED JENKINS-19830] Warn about passwords in log

            Compare: https://github.com/jenkinsci/msbuild-plugin/compare/b1b89b77e0d8...f30df9df3257

            Show
            scm_issue_link SCM/JIRA link daemon added a comment - Code changed in jenkins User: Gregory Boissinot Path: src/main/resources/hudson/plugins/msbuild/MsBuildBuilder/config.jelly src/main/webapp/help-BuildVariablesAsProperties.html http://jenkins-ci.org/commit/msbuild-plugin/f30df9df32575d31af3211e8f79f5cbea48c69b6 Log: Merge pull request #10 from jglick/mask-args- JENKINS-19830 [FIXED JENKINS-19830] Warn about passwords in log Compare: https://github.com/jenkinsci/msbuild-plugin/compare/b1b89b77e0d8...f30df9df3257
            Hide
            jglick Jesse Glick added a comment -

            Just discovered AbstractBuild.getSensitiveBuildVariables which I guess could be used for this purpose.

            Show
            jglick Jesse Glick added a comment - Just discovered AbstractBuild.getSensitiveBuildVariables which I guess could be used for this purpose.
            Hide
            scm_issue_link SCM/JIRA link daemon added a comment -

            Code changed in jenkins
            User: Gregory Boissinot
            Path:
            src/main/java/hudson/plugins/msbuild/MsBuildBuilder.java
            src/main/resources/hudson/plugins/msbuild/MsBuildBuilder/help-buildVariablesAsProperties.html
            src/main/resources/hudson/plugins/msbuild/MsBuildBuilder/help-buildVariablesAsProperties_fr.html
            http://jenkins-ci.org/commit/msbuild-plugin/03fdb89ecc2dd3a0eb06aae099baf5d90f930f49
            Log:
            Fix JENKINS-19830

            Show
            scm_issue_link SCM/JIRA link daemon added a comment - Code changed in jenkins User: Gregory Boissinot Path: src/main/java/hudson/plugins/msbuild/MsBuildBuilder.java src/main/resources/hudson/plugins/msbuild/MsBuildBuilder/help-buildVariablesAsProperties.html src/main/resources/hudson/plugins/msbuild/MsBuildBuilder/help-buildVariablesAsProperties_fr.html http://jenkins-ci.org/commit/msbuild-plugin/03fdb89ecc2dd3a0eb06aae099baf5d90f930f49 Log: Fix JENKINS-19830

              People

              • Assignee:
                kdsweeney kdsweeney
                Reporter:
                arpitgold Arpit Nagar
              • Votes:
                0 Vote for this issue
                Watchers:
                3 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: