Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-71899

Usernames are exposed in the URL while accessing user profiles

      Issue Summary

      Usernames are displayed on User profile pages within Jira.
      Example:

      Steps to Reproduce

      1. Login with Jira
      2. Navigate to user profile
      3. The profile URL displays the username information.

      Expected Results

      Username information should not appear in the Jira URL, rather it should be replaced by an externally unidentified ID.

      Actual Results

      The username appears in the URL.

      Workaround

      Currently, there is no known workaround for this behavior. A workaround will be added here when available

          Form Name

            [JRASERVER-71899] Usernames are exposed in the URL while accessing user profiles

            +1

            +1

            Kaviraj Kyatam added a comment - +1

            This bug makes it impossible to use one Jira-instance and share it with multiple customers, that should not see each other. This is a major risk at our end.

            Michael Rosenberger added a comment - This bug makes it impossible to use one Jira-instance and share it with multiple customers, that should not see each other. This is a major risk at our end.

            At least a workaround would be nice for this. Currently we are tasked with getting this vulnerability remediated.

            rob.webb@dell.com added a comment - At least a workaround would be nice for this. Currently we are tasked with getting this vulnerability remediated.

            We want to see fix this bug asap as its a major risk at our end, 

            Faisal Shamim added a comment - We want to see fix this bug asap as its a major risk at our end, 

              Unassigned Unassigned
              abrancalhao@atlassian.com Armando Neto
              Affected customers:
              11 This affects my team
              Watchers:
              12 Start watching this issue

                Created:
                Updated: