Is there something that could be done so that in the process of confirming an issue report, someone takes a look at neighboring code that may also be affected?
I discovered SECURITY-110 (October) because I tried to understand what SECURITY-79 (February) was about (of course, low and medium-but-really-should-be-low impact issues, but still). SECURITY-93 (low severity, February) looks remarkably similar to SECURITY-138 (critical, October). The former was the job config form (bf53919), the latter the Build With Parameters form (a6a7bec), therefore I assume the difference in severity. But this also means that the low severity issue description explained where a critical severity issue could be found. -- You received this message because you are subscribed to the Google Groups "Jenkins Developers" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
