Continuum
  1. Continuum
  2. CONTINUUM-1741

release.properties file containing scm credentials in plain text is visible through the Web UI

    Details

    • Type: Improvement Improvement
    • Status: Closed
    • Priority: Minor Minor
    • Resolution: Fixed
    • Affects Version/s: 1.1
    • Fix Version/s: 1.2
    • Component/s: Web - UI
    • Labels:
      None
    • Flags:
      Patch

      Description

      This is definitely a security hole. As a quickfix, the release.properties file can be hidden in the web ui until a more elegant solution in maven release is done.

        Issue Links

          Activity

          Nap Ramirez created issue -
          Hide
          Nap Ramirez added a comment -

          The quickfix intercepts requests and throws an exception when release.properties is accessed. The file listing doesn't display the release.properties file as well.

          Show
          Nap Ramirez added a comment - The quickfix intercepts requests and throws an exception when release.properties is accessed. The file listing doesn't display the release.properties file as well.
          Nap Ramirez made changes -
          Field Original Value New Value
          Attachment CONTINUUM-1741-continuum-webapp.patch [ 34147 ]
          Wendy Smoak made changes -
          Link This issue relates to MRELEASE-340 [ MRELEASE-340 ]
          Show
          Wendy Smoak added a comment - Related thread: http://www.nabble.com/Continuum-and-plain-text-passwords-td16868880.html
          Brett Porter made changes -
          Fix Version/s 1.2 [ 13779 ]
          Brett Porter made changes -
          Patch Submitted [Yes]
          Hide
          Olivier Lamy (*$^¨%`£) added a comment -

          fixed in rev 663748.
          Thanks!

          Show
          Olivier Lamy (*$^¨%`£) added a comment - fixed in rev 663748. Thanks!
          Olivier Lamy (*$^¨%`£) made changes -
          Status Open [ 1 ] Closed [ 6 ]
          Resolution Fixed [ 1 ]
          Assignee Olivier Lamy [ olamy ]
          Wendy Smoak made changes -
          Link This issue relates to CONTINUUM-2202 [ CONTINUUM-2202 ]
          Mark Thomas made changes -
          Project Import Sun Apr 05 08:36:01 UTC 2015 [ 1428222961749 ]
          Mark Thomas made changes -
          Link This issue relates to MRELEASE-340 [ MRELEASE-340 ]
          Mark Thomas made changes -
          Workflow jira [ 12710396 ] Default workflow, editable Closed status [ 12740817 ]
          Mark Thomas made changes -
          Flags Patch [ 10430 ]
          Patch Submitted Yes [ 10763 ]
          Mark Thomas made changes -
          Project Import Sun Apr 05 21:12:18 UTC 2015 [ 1428268338676 ]
          Mark Thomas made changes -
          Link This issue relates to MRELEASE-340 [ MRELEASE-340 ]
          Mark Thomas made changes -
          Workflow jira [ 12948207 ] Default workflow, editable Closed status [ 12983639 ]
          Transition Time In Source Status Execution Times Last Executer Last Execution Date
          Open Open Closed Closed
          41d 18h 1 Olivier Lamy (*$^¨%`£) 05/Jun/08 16:45

            People

            • Assignee:
              Olivier Lamy (*$^¨%`£)
              Reporter:
              Nap Ramirez
            • Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:

                Development