• 9
    • We collect Jira feedback from various sources, and we evaluate what we've collected when planning our product roadmap. To understand how this piece of feedback will be reviewed, see our Implementation of New Features Policy.

      Hi support,

      I am using Advanced Roadmap and I have noticed a security problem.

      Advanced Roadmap overrides any controls that are set in JIRA. If you have a custom fields that are not editable in JIRA, with Advanced Roadmap is anyway possible!

      The security problem is that if you use a Security Level based on a user picker field, and this is editable by anyone with Advanced Roadmap it is possible to make visible issues that normally would not be visible on Jira or are proteced by some condition rules.

      Please, check and fix as soon as possible.

       

      BR
      Antonio

          Form Name

            [JSWSERVER-24795] Advanced Roadmap allow editing of read-only fields

            SET Analytics Bot made changes -
            UIS Original: 11 New: 9
            SET Analytics Bot made changes -
            UIS Original: 8 New: 11
            SET Analytics Bot made changes -
            UIS Original: 6 New: 8
            SET Analytics Bot made changes -
            UIS Original: 4 New: 6
            SET Analytics Bot made changes -
            UIS Original: 2 New: 4
            Marc Dacanay made changes -
            Labels Original: Plan-Permiss New: Plan-Permiss ril
            Marc Dacanay made changes -
            Remote Link New: This issue links to "Internal ticket (Web Link)" [ 979417 ]
            SET Analytics Bot made changes -
            UIS Original: 4 New: 2
            SET Analytics Bot made changes -
            UIS Original: 7 New: 4
            SET Analytics Bot made changes -
            UIS Original: 9 New: 7

              Unassigned Unassigned
              1c077bceb6c9 Antonio Bosio
              Votes:
              58 Vote for this issue
              Watchers:
              34 Start watching this issue

                Created:
                Updated: