Uploaded image for project: 'Bitbucket Data Center'
  1. Bitbucket Data Center
  2. BSERV-13575

It is possible to check if a user exists in Bitbucket (either internal or external directories) on a login page

    XMLWordPrintable

Details

    Description

      Issue Summary

      It is possible to check if a user exists in Bitbucket (either internal or external directories) on a login page by typing a username & incorrect password combination.

      This is reproducible on Data Center: (yes)

      Steps to Reproduce

      1. Go to the Bitbucket logging page.
      2. Try to log in with a user that exists in any of the Bitbucket user's directories.
      3. Try to log in with a user that doesn't exist in any of the Bitbucket user's directories.

      Expected Results

      Error messages in both cases are the same:

      Actual Results

      Error messages are different in both cases allowing usernames discovery:

      User exists in a directory:

      User doesn't exist in a directory:

      Workaround

      Currently, there is no known workaround for this behavior. A workaround will be added here when available

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              ttokarczuk@atlassian.com Tomasz Tokarczuk (Inactive)
              Votes:
              1 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: