Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-8759

Security issue with unshelving project showing too much information

XMLWordPrintable

      When unshelving a project, the input value is the actual directory and name of the zip file for the shelved project.

      For example:

      aaaaaa (archived on Thu, 10 Feb 2011 16:36:22 -0600)<br /><input name="projects" value="/home/ashlux/dev/jenkins/plugins/shelve-project-plugin-plugin/./work/shelvedProjects/cccccccc-1297379255865.zip" type="checkbox" />
      cccccccc (archived on Thu, 10 Feb 2011 17:07:35 -0600)<br /><input name="projects" value="/home/ashlux/dev/jenkins/plugins/shelve-project-plugin-plugin/./work/shelvedProjects/xxxxxxx-1297377352322.zip" type="checkbox" />

            ashlux ashlux
            ashlux ashlux
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved: