1251.1253.v4e638b_e3b_221
daniel-beck
released this
16 Aug 13:31
·
118 commits
to master
since this release
Security hardening: Jobs saved by administrators will no longer result in unapproved scripts in those configurations being saved. Administrators now need to explicitly approve unapproved scripts, either through the existing UI, or by using the new inline approval button available in script field form validation messages.
The previous behavior resulted in unexpectedly approved scripts when administrators copied jobs or entire folders (approving potentially never seen scripts, similar to the hardening in 1172.v35f6a_0b_8207e), and increased the impact of SECURITY-3106 in the Folders Plugin.