Uploaded image for project: 'Jira Service Management Data Center'
  1. Jira Service Management Data Center
  2. JSDSERVER-6800

Customers created via the Customer Portal do not trigger an email verification

      In affected versions of Jira Service Desk Server and Data Centre, it was possible to create customers with fake email addresses via the Customer Portal. This is now resolved with email verification.

      Affected versions:

      • version < 3.16.13
      • 4.0.0 ≤ version < 4.5.3
      • 4.6.0 ≤ version < 4.7.0

      Fixed versions:

      • 3.16.13
      • 4.5.3
      • 4.7.0

          Form Name

            [JSDSERVER-6800] Customers created via the Customer Portal do not trigger an email verification

            David Black made changes -
            Labels Original: advisory-to-release basm no-cvss-required security New: advisory advisory-to-release basm no-cvss-required security
            David Black made changes -
            Link New: This issue relates to JSDSERVER-3762 [ JSDSERVER-3762 ]
            set-jac-bot made changes -

            Thank you!
            That's great!

            Gonchik Tsymzhitov added a comment - Thank you! That's great!
            AB made changes -
            Security Original: Atlassian Staff [ 10750 ]
            AB made changes -
            Labels Original: basm no-cvss-required security New: advisory-to-release basm no-cvss-required security
            AB made changes -
            Resolution New: Fixed [ 1 ]
            Status Original: Needs Triage [ 10030 ] New: Closed [ 6 ]
            AB made changes -
            Description Original: In affected versions of Jira Service Desk Server and Data Centre, it was possible to create customers with fake email addresses via the Customer Portal. This is now resolved with email verification.

            *Affected versions:*

             
            New: In affected versions of Jira Service Desk Server and Data Centre, it was possible to create customers with fake email addresses via the Customer Portal. This is now resolved with email verification.

            *Affected versions:*
             * version < 3.16.13
             * 4.0.0 ≤ version < 4.5.3
             * 4.6.0 ≤ version < 4.7.0

            *Fixed versions:*
             * 3.16.13
             * 4.5.3
             * 4.7.0
            AB made changes -
            Labels New: basm no-cvss-required security
            AB made changes -
            Description Original: In affected versions of Jira Service Desk Server and Data Centre, it was possible to create customers with fake email addresses via the Customer Portal. This is now resolved with email verification.

            *Affected versions:*
            New: In affected versions of Jira Service Desk Server and Data Centre, it was possible to create customers with fake email addresses via the Customer Portal. This is now resolved with email verification.

            *Affected versions:*

             

              Unassigned Unassigned
              security-metrics-bot Security Metrics Bot
              Affected customers:
              0 This affects my team
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved: