-
Bug
-
Resolution: Unresolved
-
Low
-
None
-
8.5.19, 9.2.2, 9.3.2
-
1
-
Severity 3 - Minor
-
0
-
Issue Summary
User accessing a Jira ticket that is linked to a restricted Confluence page results in a 'User tried to access restricted page' entry in 'Security' category on Confluence Audit logs. In other words, when a user views a Jira ticket that contains the Confluence page to which his/her permissions are restricted, it causes an entry in the audit logs on the Confluence side. Please note that the user never opens the restricted Confluence page(only Jira ticket is accessed).
Steps to Reproduce
- Set up Confluence and Jira. The following versions were tested:
- Confluence 9.3.2 + Jira 10.5.0 (latest releases)
- Confluence 9.2.2 + Jira 10.3.4 (latest LTS)
- Confluence 8.5.19 + Jira 9.12.15
- Setup Jira as the User directory for Confluence so that Users are shared between both products
- Setup Application link between Jira and Confluence
- Go to Audit logs settings and increase the coverage of 'Security' to Advanced or Full
- As the admin user, Create a Page in Confluence and add a Jira ticket to it using Jira issue macro
- Go to Jira and open the corresponding ticket to verify that Confluence page is reflected in the 'Issue Links - mentioned in' section
- Restrict the page so that only the admin user can view/edit it
- Login to Jira as User1 and access the corresponding Jira ticket
- User1 will see 'No Confluence page found with the given URL' message against the linked Confluence page
- Check Audit logs on the Confluence side
Expected Results
Confluence Audit log shouldn't have a Security entry because User 1 didn't access the restricted Confluence page
Actual Results
An entry gets populated in the Confluence Audit log against Security category which says 'User tried to access restricted page'
Workaround
Currently there is no known workaround for this behavior. A workaround will be added here when available
- mentioned in
-
Page Loading...