Base url can be changed without Admin challenge

XMLWordPrintable

    • Severity 3 - Minor

      The toast banner for changing Jira base url does not redirect to credential challenge page (which would be reasonable since it's a system setting).
      Was able to change base url without confirming admin credentials (though using a user which can elevate to admin).

      Have not yet been able to reproduce using a user which is not even able to elevate to admin (due to the toast-banner not appearing).

      Version is v7.1.0#71003 (no idea what the OD-versions are)

            Assignee:
            Unassigned
            Reporter:
            Thomas Stjerne
            Votes:
            1 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: