Uploaded image for project: 'Xporter for Jira'
  1. Xporter for Jira
  2. XPORTER-3644

IDOR Leads to unauthorized user perform operations on templates, audit log and settings

    XporterXMLWordPrintable

Details

    • JIRAXPORTER 2021 Sprint 1, JIRAXPORTER 2021 Sprint 2
    • OK

    Description

      Xporter Server is vulnerable to Broken Access Control -> Insecure Direct Object References by performing unauthorized operations on administration services.

      Steps to reproduce:

      Targets:

      Remediation steps: Implement a middleware to verify user permissions (JiraAdminRequired annotation).

      This issue should also be checked as a Jira Service Desk User.

      Attachments

        Issue Links

          Activity

            People

              afro Andre Fernandes Rodrigues
              prpa Paulo Alves
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - 0 minutes
                  0m
                  Remaining:
                  Remaining Estimate - 0 minutes
                  0m
                  Logged:
                  Time Spent - 1 week, 1 day, 5 hours, 25 minutes
                  1w 1d 5h 25m