Uploaded image for project: 'Xporter for Jira'
  1. Xporter for Jira
  2. XPORTER-3159

Xporter returns sensitive information on File Servers Rest Service.

    XporterXMLWordPrintable

Details

    • OK

    Description

      Xporter returns crucial information on File Servers Rest Service.
      Using the following RES API call, the user is able to get crucial information such as File Server password.

      http://<JIRA_BASE_URL>/jira/jiraxporter/1.0/servers/?context=admin
      

      Expected behavior:

      • The rest service should return only non-crucial information.
      • Password must be asked when the user wants to edit a file server in order to avoid passing the password

      Attachments

        Issue Links

          Activity

            People

              rmbr Rui Rodrigues
              afro Andre Fernandes Rodrigues
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - 0 minutes
                  0m
                  Remaining:
                  Remaining Estimate - 0 minutes
                  0m
                  Logged:
                  Time Spent - 7 hours
                  7h