Le 31 déc. 2016 1:08 AM, "Daniel Beck" <[email protected]> a écrit :


> On 30.12.2016, at 15:27, Baptiste Mathus <[email protected]> wrote:
>
> Did you try the global 
> -Dhudson.model.ParametersAction.keepUndefinedParameters=true
switch?
>

It's a good idea not to disable this security entirely if the threat
described in the advisory is relevant, so
hudson.model.ParametersAction.safeParameters
is a better approach IMO.


> At least, if the global one works, it will narrow down the scope of
research here, so IMO worth trying.

Agreed. Again, I was advising that only to narrow down the issue possibly.
Not just to use that instead and Yolo.


--
You received this message because you are subscribed to the Google Groups
"Jenkins Users" group.
To unsubscribe from this group and stop receiving emails from it, send an
email to [email protected].
To view this discussion on the web visit https://groups.google.com/d/
msgid/jenkinsci-users/51F00B79-D3E0-4AF1-9D6D-56A888ADD78B%40beckweb.net.
For more options, visit https://groups.google.com/d/optout.

-- 
You received this message because you are subscribed to the Google Groups 
"Jenkins Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/jenkinsci-users/CANWgJS6ni11m1Q7QWnPhDvk7R7CLCaeiksYCDVWCrpiisngDSQ%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to