SECURITY-746 - Promoted Builds Plugin allowed unauthorized users to run some promotion processes
Users with Job/Read access were able to approve and re-execute promotion processes with a manual promotion condition that did not specify a list of users allowed to manually approve the promotion.
The plugin now requires users to have the Promotion/Promote permission to be able to approve or re-execute a promotion with manual condition that does not specify a list of users allowed to approve it.
Comments
1 comment
The recent CloudBees Security Advisory 2018-02-26 relates to this.
https://www.cloudbees.com/cloudbees-security-advisory-2018-02-26
SECURITY-746 - Promoted Builds Plugin allowed unauthorized users to run some promotion processes
Users with Job/Read access were able to approve and re-execute promotion processes with a manual promotion condition that did not specify a list of users allowed to manually approve the promotion.
The plugin now requires users to have the Promotion/Promote permission to be able to approve or re-execute a promotion with manual condition that does not specify a list of users allowed to approve it.
Please sign in to leave a comment.