Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-44244

Any user can add Scriptler script build steps to job configurations

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Blocker Blocker
    • scriptler-plugin
    • None

       

      SECURITY-365
      Scriptler plugin lets users with Overall/Run Scripts or Overall/Administer permission add Scriptler script executions to job configurations. Users without these permissions are not supposed to be able to add this build step to jobs.
      The protection mechanism used only affects submission of job configuration forms through the UI and can be circumvented e.g. by sending POST config.xml requests.

            imod Dominik Bartholdi
            imod Dominik Bartholdi
            Votes:
            1 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated: