-
Type:
Bug
-
Resolution: Unresolved
-
Priority:
Low
-
None
-
Affects Version/s: 10.3.10, 10.3.12
-
Component/s: Webhooks
-
None
-
10.03
-
2
-
Severity 3 - Minor
-
6
Issue Summary
Prior to Jira version 10.3.10, any user could view the profile of another user involved in a Jira ticket, regardless of their role. Starting with Jira 10.3.10, however, admin users are now required to have WebSudo access to view other users’ profiles. Regular users can still view other users’ profiles without needing WebSudo access.
Steps to Reproduce
- Create any Jira issue.
- Login with any admin user and try to view the profile of a user playing any role on the issue created in Step 1 and notice that admin user is required to have WebSudo access.

- Now perform same steps with any non-admin user and they are able to view the other users profile without any WebSudo access.
Expected Results
Admin users should be able to view other users’ profiles from Jira issue view without any WebSudo authentication.
Actual Results
Admin users requires WebSudo authentication to view other users’ profiles.
Workaround
Admin needs to authenticate via WebSudo to see other users profile from Issue View.