Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-29645

Information disclosure in REST API

    XMLWordPrintable

Details

    Description

      REST endpoints to search groups and to list issue resolutions allow anonymous/unauthenticated access.

      The former allows to enumerate all groups on a JIRA instance (by sending multiple queries as results are limited by jira.ajax.autocomplete.limit). We've verified this on an instance without any public projects / groups / whatsoever running version 5.1.1.

      For an example see:
      https://jira.atlassian.com/rest/api/2/groups/picker
      https://jira.atlassian.com/rest/api/2/resolution

      Attachments

        Activity

          People

            rtekhov Roman Tekhov (Inactive)
            patrick.otto Patrick Otto
            Votes:
            0 Vote for this issue
            Watchers:
            8 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: