Uploaded image for project: 'Xporter for Jira'
  1. Xporter for Jira
  2. XPORTER-2814

Security breach regarding Permission schemes when a JQL iteration is defined on templates

    XporterXMLWordPrintable

Details

    • OK

    Description

      Through JQL expression, it is possible to export all information in jira, bypassing the security that may exist (using permission schemes).

      Steps to reproduce:

      1. Disable Xporter for all users and projects
      2. Create a project called "DEMO"
      3. Create a permission scheme to allow export Stories from DEMO project.
      4. Create a template with a JQL iteration where the JQL query return issues from another project, for example
      5. Install the template
      6. Go to a DEMO Story issue and export using the template created.

       

      Attachments

        1. Capturar.PNG
          Capturar.PNG
          7 kB
        2. Capturar1.PNG
          Capturar1.PNG
          10 kB
        3. JQL_Oracle (6).docx
          12 kB
        4. JQL_Oracle (6) (2).docx
          10 kB

        Issue Links

          Activity

            People

              rmbr Rui Rodrigues
              tfsi Tiago Silva [X] (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - 0 minutes
                  0m
                  Remaining:
                  Remaining Estimate - 0 minutes
                  0m
                  Logged:
                  Time Spent - 1 day, 6 hours, 45 minutes
                  1d 6h 45m