Uploaded image for project: 'Xporter for Jira'
  1. Xporter for Jira
  2. XPORTER-3655

IDOR Leads to unauthorised user perform operations Single, Bulk, XLSX and JSD Queues exportation

    XporterXMLWordPrintable

Details

    • JIRAXPORTER 2021 Sprint 2
    • OK

    Description

      Xporter Server is vulnerable to Broken Access Control -> Insecure Direct Object References by performing unauthorized operations on different exportations.

      Steps to reproduce:

      • Access the Xporter (Bulk Export) and should be able to perform the exportation

       

      Targets:

      • Single Export (please be aware the Key is different on the request)
      • Bulk Export (please be aware the Key is different on the request)
      • XLSX Current Fields
      • JSD Queues

       

      Also, validate:

      • JSD
        • Ticket Detail
        • Ticket List
      • Agile Boards
        • Kanban Board
        • Release board
        • Active Sprint
        • Backlog
      • Structure

       

      How to fix:

      We should use Conditions on Atlassian plugin.xml instead of passing the value through REST API

       

      Attachments

        Activity

          People

            afro Andre Fernandes Rodrigues
            afro Andre Fernandes Rodrigues
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0 minutes
                0m
                Logged:
                Time Spent - 1 week, 1 day, 2 hours
                1w 1d 2h