Information leak: Project Custom Field Type links to browse project regardless of user permission

XMLWordPrintable

    • 3.12

      Although the browse project page will not be displayed without sufficient permission, in other areas of JIRA, the existence of a project is hidden unless the user has no permission to see it.

      The project cf type should not show the project at all if the user doesn't have permission to see it.

              Assignee:
              Michael Tokar
              Reporter:
              Chris Mountford
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved:

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 2.5h
                  2.5h