Branch: refs/heads/master Home: https://github.com/jenkinsci/libvirt-slave-plugin Commit: 655eab9bde26e8b8e11034f6c405af374564cae7 https://github.com/jenkinsci/libvirt-slave-plugin/commit/655eab9bde26e8b8e11034f6c405af374564cae7 Author: Bastian Germann <b...@linutronix.de> Date: 2021-03-03 (Wed, 03 Mar 2021)
Changed paths: M CHANGELOG.md M src/main/java/hudson/plugins/libvirt/VirtualMachineManagementServer.java Log Message: ----------- Only allow POST verb on VM control submit This addresses SECURITY-1764 additionally to d6a07fede6 ("Add missing permission checks to list box model functions"). Signed-off-by: Bastian Germann <b...@linutronix.de> Reviewed-by: Benedikt Spranger <b.spran...@linutronix.de> Commit: b9c8dcc2dc642952d84065fac37c92c5504189a5 https://github.com/jenkinsci/libvirt-slave-plugin/commit/b9c8dcc2dc642952d84065fac37c92c5504189a5 Author: Bastian Germann <b...@linutronix.de> Date: 2021-03-03 (Wed, 03 Mar 2021) Changed paths: M src/main/java/hudson/plugins/libvirt/VirtualMachineSlave.java Log Message: ----------- Add missing permission checks to list box model function doFillHypervisorDescriptionItems lacks a proper permission check and may leak information about existing virtual agents. Add permission checks to the function. Signed-off-by: Bastian Germann <b...@linutronix.de> Commit: df9753cfa7fbefa1f64880dcf393a8fe4d466b82 https://github.com/jenkinsci/libvirt-slave-plugin/commit/df9753cfa7fbefa1f64880dcf393a8fe4d466b82 Author: Bastian Germann <b...@linutronix.de> Date: 2021-03-03 (Wed, 03 Mar 2021) Changed paths: M src/main/java/hudson/plugins/libvirt/Hypervisor.java M src/main/java/hudson/plugins/libvirt/lib/ConnectionBuilder.java M src/main/java/hudson/plugins/libvirt/util/Consts.java M src/main/resources/hudson/plugins/libvirt/Hypervisor/config.jelly M src/main/webapp/help-libvirt-hypervisorHost.html M src/main/webapp/help-libvirt-hypervisorSshPort.html M src/main/webapp/help-libvirt-username.html Log Message: ----------- Generalize port settings The port settings imply that SSH is the only transport that can be used, while the default is TLS. Make the help texts and default behaviour more general. Signed-off-by: Bastian Germann <b...@linutronix.de> Commit: 22a2d8e350154390c8d6913925e8ca37992291b8 https://github.com/jenkinsci/libvirt-slave-plugin/commit/22a2d8e350154390c8d6913925e8ca37992291b8 Author: Bastian Germann <b...@linutronix.de> Date: 2021-03-03 (Wed, 03 Mar 2021) Changed paths: M README.md Log Message: ----------- README: Remove too specific/wrong info Signed-off-by: Bastian Germann <b...@linutronix.de> Commit: b649ad4341724c721714f4500944dd136bcf17e7 https://github.com/jenkinsci/libvirt-slave-plugin/commit/b649ad4341724c721714f4500944dd136bcf17e7 Author: Bastian Germann <b...@linutronix.de> Date: 2021-03-04 (Thu, 04 Mar 2021) Changed paths: M CHANGELOG.md Log Message: ----------- Prepare release Signed-off-by: Bastian Germann <b...@linutronix.de> Compare: https://github.com/jenkinsci/libvirt-slave-plugin/compare/7c545b52fadd...b649ad434172 -- You received this message because you are subscribed to the Google Groups "Jenkins Commits" group. To unsubscribe from this group and stop receiving emails from it, send an email to jenkinsci-commits+unsubscr...@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/jenkinsci-commits/jenkinsci/libvirt-slave-plugin/push/refs/heads/master/7c545b-b649ad%40github.com.