Uploaded image for project: 'Crowd Data Center'
  1. Crowd Data Center
  2. CWD-163

Administration Console allows login of unauthorized users

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • High
    • 1.0.3
    • 0.4.4
    • Core features
    • None

    Description

      When a valid (but unauthorized) principal (user) of Crowd tries to login to the Administration Console after an (authorized) administrator has been logged in and then logged out on the same computer, this unauthorized principal will be granted access to the Administration Console during some time window (approx. 5 minutes).

      Clearing all cookies in the browser when the authorized admin has logged out doesn't help to avoid the problem. Expiring the session in the Administration Console doesn't help either - the login will be successful again when performed within the time window.

      Ironically if this unauthorized principal (when being logged in) surfs to Applications - Crowd - Config Test and provides his credentials there, he is (correctly) rejected ("Invalid verification").

      Attachments

        Issue Links

          Activity

            People

              shamid@atlassian.com shihab
              cd6347d59f92 Bernd Rinn
              Votes:
              1 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: