RE: Why is Jenkins suddenly telling me about an old security vulnerability

2018-10-22 Thread matthew.web...@diamond.ac.uk
ober 2018 18:02 > To: Jenkins Users > Subject: Re: Why is Jenkins suddenly telling me about an old security > vulnerability > > This is supposed to only show when Jenkins detects an upgrade from 1.495 or > older. IIRC, it uses information from the global config.xml to determine

Re: Why is Jenkins suddenly telling me about an old security vulnerability

2018-10-19 Thread Daniel Beck
This is supposed to only show when Jenkins detects an upgrade from 1.495 or older. IIRC, it uses information from the global config.xml to determine that. Any scripting messing with this file could be a possible culprit. I recommend not executing this. I'm not sure whether the format of secrets

Why is Jenkins suddenly telling me about an old security vulnerability

2018-10-19 Thread matthew.web...@diamond.ac.uk
We recently upgraded Jenkins from 2.146 to 2.147 (which is the newest release at the time of writing). Since then, Jenkins has displayed a message in the WebUI: "Because of a security vulnerability discovered earlier, we need to change the encryption key used to protect secrets in your configura