Uploaded image for project: 'Bamboo Data Center'
  1. Bamboo Data Center
  2. BAM-21846

User's password can be viewed in the plan variables page

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Medium Medium
    • 9.0.0, 8.2.6, 8.1.10
    • 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.1.1, 8.0.4, 8.0.5, 8.1.2, 8.0.6, 8.2.0, 8.1.3, 8.0.7, 8.1.4, 8.2.1, 8.1.5, 8.2.2, 8.1.6, 8.0.8, 8.1.7, 8.2.3, 8.1.8, 8.2.4, 8.0.9, 8.0.10, 8.1.9, 8.2.5
    • Security, Variables
    • None

      Issue Summary

      User's password can be viewed in the plan variables page.

      This is reproducible on Data Center: yes

      Steps to Reproduce

      1. Login to Bamboo and save the credentials using the Chrome or other browser password management tool;
      2. Go to plan settings >> Variables and type on the variable name field the user name saved previously
      3. Now it's possible to select the user's password on the variable value. The password is not encrypted and can be viewed.

      Expected Results

      Not show the user's password on the plan variables page.

      Actual Results

      User's password is shown.

      Workaround

      Currently there is no known workaround for this behavior. A workaround will be added here when available.

        1. screenshot-1.png
          screenshot-1.png
          127 kB
        2. screenshot-2.png
          screenshot-2.png
          49 kB

              72548a1cec6d Wioletta Dys
              kmiranda Karel Miranda
              Votes:
              2 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: