Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-73313

AutoComplete Attribute Not Disabled for Password in Form Based Authentication

    XMLWordPrintable

Details

    • 25
    • We collect Jira feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

    Description

      This came out in a recent security scan our internal Cyber Security team ran against both UAT and Production Jira environments.

      The Web server allows form based authentication without disabling the AutoComplete feature for the password field.

      If the browser is used in a shared computing environment where more than one person may use the browser, then "autocomplete" values may be retrieved or submitted by an unauthorized user.

      Contact the vendor to have the AutoComplete attribute disabled for the password field in all forms. The AutoComplete attribute should also be disabled for the user ID field.
      Developers can add the following attribute to the form or input element: autocomplete="off"
      This attribute prevents the browser from prompting the user to save the populated form values for later reuse.

      We need a way to disable AutoComplete in the login screen from inside the Jira GUI or by any other means that is actually supported by Atlassian.

      Attachments

        Issue Links

          Activity

            People

              pdrygas Pawel Drygas (Inactive)
              87d00aa6f735 Pedro Caba
              Votes:
              29 Vote for this issue
              Watchers:
              36 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: