JIRA includes the Username in links on the edit profile page

XMLWordPrintable

    • Severity 3 - Minor

      This can pose a security issue. For example, information about the username can be used to perform dictionary attacks on the login page. Suggest just using the username stored in the session while editing your own profile, or a POST for editing other users

      Steps to Reproduce:
      1. Go to View Ossue page.
      2. Click on the user in the user detail pop-up. Notice the username in the URL.

            Assignee:
            Unassigned
            Reporter:
            tyler.x.miller.-nd
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: