Description
Issue Summary
When Bamboo is upgraded from old version before 5.x, entries in the table VARIABLE_SUBSTITUTION are migrated to a different table. However, the table and its values remaining uncleaned. This results in some sensitive variable values appearing unencrypted in the database.
Expected Results
The table must be deleted or the contents in it must be cleared.
Actual Results
The old entries remain intact in the table; thereby resulting in displaying some sensitive old variable values in plaintext.
Workaround
Manually delete the contents of this table.
Attachments
Issue Links
- is related to
-
BAM-16132 Large variable_context table causing database to deadlock when build expiry runs
- Closed