-
Bug
-
Resolution: Unresolved
-
Medium
-
None
-
5.0.5
-
5
-
2
-
Severity 2 - Major
-
It seems that a user without access to a certain project, can still see the information on issue linking on the Activity and All Tab.
To replicate this problem:
- Create two projects, Project A and Project B
- Project A has Browse Permission to Group (Anyone)
- Project B has Browse Permission to Project Role (Developer)
- And Project B has linking Permission: Project Role (Developer)
- Create a ticket for both projects
- A user belongs to the Project Role Developer link an issue from Project A to B
- User who does not have access to project B should not know about the existence of Project B
- The result/action of this issue linking will still be stored on the Activity and All tab
Tested this behavior on JIRA 4.4.1 and 5.0.5
- is duplicated by
-
JRASERVER-43319 Information disclosure in the change history tab - Issue Links
- Closed
-
JRASERVER-41043 Linked Issues displayed in History tab, regardless of permissons
- Gathering Impact
- relates to
-
JRASERVER-63246 Hide issue links to issues in remote JIRA instances when user not able to view remote issues
- Gathering Interest