Issue Summary
User's password can be viewed in the plan variables page.
This is reproducible on Data Center: yes
Steps to Reproduce
- Login to Bamboo and save the credentials using the Chrome or other browser password management tool;
- Go to plan settings >> Variables and type on the variable name field the user name saved previously
- Now it's possible to select the user's password on the variable value. The password is not encrypted and can be viewed.
Expected Results
Not show the user's password on the plan variables page.
Actual Results
User's password is shown.
Workaround
Currently there is no known workaround for this behavior. A workaround will be added here when available.
- mentioned in
-
Page Loading...