• Icon: Bug Bug
    • Resolution: Fixed
    • Icon: High High
    • 4.12.0
    • 4.10.1
    • None

      Certain permissions relating to Default Reviewers could be circumvented by authenticated users.

            [BSERV-9392] Permission issue when configuring Default Reviewers

            Owen made changes -
            Workflow Original: Stash Workflow - Restricted [ 1630056 ] New: JAC Bug Workflow v3 [ 3136285 ]
            Owen made changes -
            Symptom Severity Original: Major [ 14431 ] New: Severity 2 - Major [ 15831 ]
            Adam Ahmed (Inactive) made changes -
            Security Original: Reporter and Atlassian Staff [ 10751 ]
            Matt Hart (Inactive) made changes -
            Description Original: Certain permissions relating to Default Reviewers could be circumvented by logged-in users. New: Certain permissions relating to Default Reviewers could be circumvented by authenticated users.
            Adam Ahmed (Inactive) made changes -
            Description Original: Logged in u New: Certain permissions relating to Default Reviewers could be circumvented by logged-in users.
            Adam Ahmed (Inactive) made changes -
            Resolution New: Fixed [ 1 ]
            Status Original: Needs Triage [ 10030 ] New: Closed [ 6 ]
            Adam Ahmed (Inactive) made changes -
            Labels Original: bplump-radar cvss-medium expedite security New: cvss-medium security
            Adam Ahmed (Inactive) made changes -
            Summary Original: Non-admins can access Default Reviewers Page New: Permission issue when configuring Default Reviewers
            Adam Ahmed (Inactive) made changes -
            Description Original: h3. Summary

            Anyone with permissions to a repository can access the Default Reviewer admin page if they know the URL.

            [http://localhost:7990/plugins/servlet/default-reviewers/projects/$project/repos/$repo]
            h3. Steps to Reproduce
             # Login as a non-admin to Bitbucket and go to the URL above.
             # Add or remove default reviewers

            h3. Expected Results

            Only repository admins should be able to access this page.
            h3. Actual Results

            Anyone *with permissions to a repository* can access and modify default reviewers.
            New: Logged in u
            Adam Ahmed (Inactive) made changes -
            Link New: This issue is cloned from BSERV-9316 [ BSERV-9316 ]

              crolf Christian
              bstuart Ben Stuart (Inactive)
              Affected customers:
              0 This affects my team
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: