-
Type:
Sub-task
-
Resolution: Fixed
-
Priority:
Medium
-
Affects Version/s: August 2011
-
Component/s: JIRA
-
Environment:
Studio JIRA 4.4 integration branch
106 r126609
In the June release, the "User Sessions" admin page was visible to both admins and sysadmins, but the link to it was not visible to admins.
In July, the link is now admin-visible.
This page shows information about the current HTTP sessions of all users, including their internal session ID (not JSESSIONID). It doesn't seem to show anything exploitable.

Is this intentional or was this page never meant to be accessible to admins?