ocf / ocflib

Python libraries for account and server management
https://pypi.python.org/pypi/ocflib
Other
15 stars 32 forks source link

Test if non-contributors can trigger custom builds #132

Closed xcfbot closed 6 years ago

xcfbot commented 6 years ago

Would be an remote code execution if so, but Jenkins should protect against some of this (changing the Jenkinsfile specifically)

(actually made by @jvperrin)

xcfbot commented 6 years ago

Loading trusted files from base branch master at a17b92180532eb68b22dfb5aaf652897e4e8e9c7 rather than 2fbbe19473029933e2bb6c3bf33a2f4b617d3432

Looks like modifying the Jenkinsfile itself is prevented, as I expected, but modifying other files should still work and #131 should prevent that.