Crucible: Default “Global Anonymous” settings allow unauthenticated users full access to user lists, projects, source code and code review information.

XMLWordPrintable

    • Type: Public Security Vulnerability
    • Resolution: Fixed
    • Priority: Low
    • 4.8.13
    • Affects Version/s: 4.8.12
    • Component/s: None
    • 5.9
    • Information Disclosure

      To prevent anonymous access by default:

      Global Anonymous access: set OFF
      Crucible Anonymous access: set OFF
      Public Signup: set OFF
      User List Visibility: set Visible to logged in users only

            Assignee:
            Unassigned
            Reporter:
            Artem Iurkov (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: