Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-53385

users with job/configure and job/build priviledge can access sensitive secrets and may commit modifications

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Not A Defect
    • Icon: Critical Critical
    • core
    • None

      If a jenkins user has job/configure and job/build priviledge and can run build on master, he can run a shell script to get all data in JENKINS_HOME, including all of jekins secret tokens and all of personal secrets of jenkins users.

      Apparently, he can also modify configuration files on disk, even though the modification will not take effects immediately.

      Please fix it!

            Unassigned Unassigned
            worraps Bin Tian
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: