Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-14794

Information leak: Project Custom Field Type links to browse project regardless of user permission

XMLWordPrintable

      Although the browse project page will not be displayed without sufficient permission, in other areas of JIRA, the existence of a project is hidden unless the user has no permission to see it.

      The project cf type should not show the project at all if the user doesn't have permission to see it.

            mtokar Michael Tokar
            chris@atlassian.com Chris Mountford
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0h
                0h
                Logged:
                Time Spent - 2.5h
                2.5h