Uploaded image for project: 'Crowd Data Center'
  1. Crowd Data Center
  2. CWD-3467

Crowd OpenID server does not enforce profile ownership for viewing

XMLWordPrintable

      Similar to CWD-3465, it seems that not enforce profile ownership for viewing. That is, a non-admin user called Mallory can view Alice's profile information if Mallory obtains Alice's profileId number. For example, https://openid.atlassian.com/secure/profile/editprofiles.action?profileID=15240744 shows you my profile details.

              Unassigned Unassigned
              dblack David Black
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: