Injecting arbitrary parameters is now forbidden, so the plugin should declare them to the jobs.
Undeclared vars are not present anymore
Release Plugin was listed on the page: https://wiki.jenkins-ci.org/display/JENKINS/Plugins+affected+by+fix+for+SECURITY-170 and no issue was yet created for this.
|Field||Original Value||New Value|
|Assignee||Peter Hayes [ petehayes ]||Antonio Muñiz [ amuniz ]|
|Status||Open [ 1 ]||In Progress [ 3 ]|
|Priority||Major [ 3 ]||Blocker [ 1 ]|
|Remote Link||This issue links to "PR (Web Link)" [ 14363 ]|
|Workflow||JNJira [ 171202 ]||JNJira + In-Review [ 185747 ]|
|Comment||[ PR has been updated to respond to comments. Pending re-reviews. ]|
|Status||In Progress [ 3 ]||Resolved [ 5 ]|
|Resolution||Fixed [ 1 ]|