From Jira 10.3.10 and later version, admin users requires WebSudo access when viewing other users profile from Issue View but non-admin users can view without any WebSudo.

XMLWordPrintable

    • Type: Bug
    • Resolution: Unresolved
    • Priority: Low
    • None
    • Affects Version/s: 10.3.10, 10.3.12
    • Component/s: Webhooks
    • None
    • 10.03
    • 2
    • Severity 3 - Minor
    • 6

      Issue Summary

      Prior to Jira version 10.3.10, any user could view the profile of another user involved in a Jira ticket, regardless of their role. Starting with Jira 10.3.10, however, admin users are now required to have WebSudo access to view other users’ profiles. Regular users can still view other users’ profiles without needing WebSudo access.

      Steps to Reproduce

      1. Create any Jira issue.
      1. Login with any admin user and try to view the profile of a user playing any role on the issue created in Step 1 and notice that admin user is required to have WebSudo access.
      1. Now perform same steps with any non-admin user and they are able to view the other users profile without any WebSudo access.

      Expected Results

      Admin users should be able to view other users’ profiles from Jira issue view without any WebSudo authentication.

      Actual Results

      Admin users requires WebSudo authentication to view other users’ profiles.

      Workaround

      Admin needs to authenticate via WebSudo to see other users profile from Issue View.

            Assignee:
            Karol Skwierawski
            Reporter:
            Karan Ahuja
            Votes:
            1 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated: