Logging in as a Non-admin user without Browse User Permission can view User Profiles

XMLWordPrintable

    • 7.05
    • 1
    • Severity 2 - Major

      Summary

      When a non-admin user access JIRA and directly hit the URL (assuming that he knows other users' username), he would be able to view his/her profile though no Browse User permission is granted.

      Steps to Reproduce

      1. Create a test user and grant an application access
      2. Ensure that no Browse User permission is granted to this user
      3. Access the Base URL and append secure/ViewProfile.jspa?name=anyusername at the end of the Base URL.

      Expected Behavior

      User is not able to view the profile.

      Actual Result

      User is able to see the other user's profile as long as he knows the username.

      Workaround

      None

            Assignee:
            Unassigned
            Reporter:
            Anna Cardino (Inactive)
            Votes:
            1 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved: