Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Done
-
4.2.3
-
XRAY 2020 Sprint 10, XRAY 2020 Sprint 11, XRAY 2020 Sprint 12
-
Description
- Create Jira user with no_permissions.
- Create a Xray project and configure this project permission settings for administrator only
- Create a TEST Manual with 3 steps
- using the user with no permission, call
curl -H "Content-Type: application/json" -X POST -u sin:sin -d '{"index":1}' "http://localhost:8120/rest/raven/1.0/customFields/move?testKey=TOM-1&id=121551"
Attachments
Issue Links
- clones
-
XRAY-6820 IDOR Leads to unauthorized user to delete attachment on Test issue [Manual Steps]
- Closed