Uploaded image for project: 'Bamboo Data Center'
  1. Bamboo Data Center
  2. BAM-13974

Global variable password values exposed with REST expand=variableContext

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • High
    • 5.3
    • 5.1
    • REST API, Security
    • None

    Description

      http://server:8085/rest/api/latest/plan/PROJECTKEY-PLANKEY/JOBKEY?expand=variableContext

      This occurs even if logged in with just use authority. Given you made passwords not visible with build results, it seems strange they are exposed this way.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              bob.swift@charter.net Bob Swift OSS (Bob Swift Atlassian Apps)
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: