-
Suggestion
-
Resolution: Unresolved
-
None
-
11
-
Hi support,
I am using Advanced Roadmap and I have noticed a security problem.
Advanced Roadmap overrides any controls that are set in JIRA. If you have a custom fields that are not editable in JIRA, with Advanced Roadmap is anyway possible!
The security problem is that if you use a Security Level based on a user picker field, and this is editable by anyone with Advanced Roadmap it is possible to make visible issues that normally would not be visible on Jira or are proteced by some condition rules.
Please, check and fix as soon as possible.
BR
Antonio
- is related to
-
JRACLOUD-87937 Plans (Advanced Roadmap) allow editing of read-only fields
- Closed
- links to
Form Name |
---|
So is there no solution to this?? This is a severe security issue !!