Uploaded image for project: 'Bamboo Data Center'
  1. Bamboo Data Center
  2. BAM-3239

REST API updateAndBuild.action can be abused if no IP address is specified

    • Icon: Suggestion Suggestion
    • Resolution: Obsolete
    • None
    • REST API
    • None
    • 0
    • 1
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      currently no authorization is required - updateAndBuild.action is designed to work with repository scripts to push builds from the repository server. It is not designed to be used by 'users' from a random IP address. Thus the IP address of the repository has to be specified to make this command api call safe. Otherwise it is not safe and can be abused. The IP address field should not be optional. It should be dedicated to the repository IP address to avoid a possible remote attack.

            [BAM-3239] REST API updateAndBuild.action can be abused if no IP address is specified

            No work has yet been logged on this issue.

              Unassigned Unassigned
              ukuhnhardt Ulrich Kuhnhardt [Atlassian]
              Votes:
              1 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: