Uploaded image for project: 'Jira Service Management Cloud'
  1. Jira Service Management Cloud
  2. JSDCLOUD-5856

Restricted Confluence pages are being suggested to customers at Customer Portal when jira-servicedesk-users group is used to restrict page access in Confluence

      Steps to Reproduce

      1. Create a Space in Confluence.
      2. Add multiple pages to this Space.
      3. Choose a single page and restrict access to jira-servicedesk-users in the padlock icon.
      4. Create a JIRA Service Desk project
      5. Access Project settings > Knowledgebase
      6. Link to the Confluence space created
      7. Access Portal as user not listed at jira-servicedesk-users group (customer)
      8. Perform a search for the restricted page

      Actual Results

      Customers are suggested with the restricted pages even if they are not part of jira-servicedesk-users group

      Expected Results

      The page should not be displayed to users without the permission to view the Confluence page.

      Workaround

      Use a specific Confluence space for the knowledge base that only contains pages you wish to share with Service Desk users. Or use another group, except jira-servicedesk-users, to restrict page access in Confluence.

            [JSDCLOUD-5856] Restricted Confluence pages are being suggested to customers at Customer Portal when jira-servicedesk-users group is used to restrict page access in Confluence

            (Resetting the security bugfix sla for this issue as this project will now be tracked ).
            (Resetting the security bugfix sla for this issue at the request of dnguyen@atlassian.com)
            CVSS v3 score: 5.0 => Medium severity

            Exploitability Metrics

            Attack Vector Network
            Attack Complexity Low
            Privileges Required Low
            User Interaction None

            Scope Metric

            Scope Changed

            Impact Metrics

            Confidentiality Low
            Integrity None
            Availability None

            See http://go.atlassian.com/cvss for more details.

            https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

            David Black added a comment - (Resetting the security bugfix sla for this issue as this project will now be tracked ). (Resetting the security bugfix sla for this issue at the request of dnguyen@atlassian.com ) CVSS v3 score: 5.0 => Medium severity Exploitability Metrics Attack Vector Network Attack Complexity Low Privileges Required Low User Interaction None Scope Metric Scope Changed Impact Metrics Confidentiality Low Integrity None Availability None See http://go.atlassian.com/cvss for more details. https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

              dnguyen@atlassian.com Duy Nguyen JSM
              fcouto Coutinho (Inactive)
              Affected customers:
              2 This affects my team
              Watchers:
              10 Start watching this issue

                Created:
                Updated:
                Resolved: