Is there something that could be done so that in the process of confirming an 
issue report, someone takes a look at neighboring code that may also be 
affected?

I discovered SECURITY-110 (October) because I tried to understand what 
SECURITY-79 (February) was about (of course, low and 
medium-but-really-should-be-low impact issues, but still).

SECURITY-93 (low severity, February) looks remarkably similar to SECURITY-138 
(critical, October). The former was the job config form (bf53919), the latter 
the Build With Parameters form (a6a7bec), therefore I assume the difference in 
severity. But this also means that the low severity issue description explained 
where a critical severity issue could be found.

-- 
You received this message because you are subscribed to the Google Groups 
"Jenkins Developers" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to