-
Bug
-
Resolution: Duplicate
-
Low
-
Severity 2 - Major
-
Summary
Last Nov 23-26, an app vendor received more than 35+ user_deleted webhook events within seconds with user name's like "removed1", "removedX". These events are received for all Jira instances the app is installed and is loading the vendor's server.
Sample log:
2018-11-26T17:39:06+05:30 [info] application - User delete webhook event for instance = https://{instance-name}.atlassian.net with request body json = {"timestamp":1543234145911,"webhookEvent":"user_deleted","user":{"name":"removed58"}} 2018-11-26T17:39:06+05:30 [info] application - User delete webhook event for instance = https://{instance-name}.atlassian.net with request body json = {"timestamp":1543234145935,"webhookEvent":"user_deleted","user":{"name":"removed12"}} 2018-11-26T17:39:06+05:30 [info] application - User delete webhook event for instance = https://{instance-name}.atlassian.net with request body json = {"timestamp":1543234145947,"webhookEvent":"user_deleted","user":{"name":"removed77"}}
Notes
- Checked audit logs of affected instances and there's no trace of user deletion
Real sample log in linked issues
- duplicates
-
ACJIRA-1379 Repeated delete user webhook calls
- Closed
- relates to
-
DEVHELP-1949 Failed to load
Form Name |
---|