Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Critical - users working as other user

Dmitry
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
November 23, 2022

Hi everybodies

I have JS 8.20.7 / JSM 4.20.7

And today i got reclamation not first time 

My users (JS) and customers (JSM only portal access) after open browser got profile other user. Both saw the same wrong name.
Example today:
* UserA open browser in JS interface without login (because system remembers him) and can't see filter which he created early. He checked profile - and it's no he, there other UserB. UserA twice clicked (first try unsuccsesfull) on logout and relogon correctly.
* At the same time CunsomerC open portal and was redirected to profile portal page for UserB

It's incredible - all users and customers fear for security the data.
Does anyone know what's going on?

Part of log file - UserB has some different IP, including IP other Counry, other provider and building

2022-11-23 09:13:52,999+0600 http-nio-8080-exec-214 INFO UserB 553x280213x1 1qt9tdw 10.10.x.x,192.169.x.x,127.0.0.1 /secure/AjaxIssueAction!default.jspa [c.a.jira.security.WorkflowBasedPermissionManager] ADD_COMMENTS granted by permission scheme but DENIED by workflow
2022-11-23 09:28:07,088+0600 http-nio-8080-exec-151 INFO UserB 568x283059x2 1b1uzzh 94.158.x.x,192.169.x.x,127.0.0.1 /servicedesk/customer/portals [c.a.j.p.assets.impl.AssetStorageManagerImpl] Can't find asset: com.atlassian.servicedesk/banner.json: Path does not exist
2022-11-23 09:37:12,824+0600 http-nio-8080-exec-207 INFO UserB 577x285353x1 1b1uzzh 31.31.x.x,192.169.x.x,127.0.0.1 /servicedesk/customer/user/profile [c.a.j.p.assets.impl.AssetStorageManagerImpl] Can't find asset: com.atlassian.servicedesk/banner.json: Path does not exist
2022-11-23 09:37:31,165+0600 http-nio-8080-exec-135 INFO UserB 577x285520x2 1b1uzzh 212.42.x.x,192.169.x.x,127.0.0.1 /rest/servicedesk/1/customer/models [c.a.j.p.assets.impl.AssetStorageManagerImpl] Can't find asset: com.atlassian.servicedesk/banner.json: Path does not exist

 

 

1 answer

1 accepted

2 votes
Answer accepted
Rilwan Ahmed
Community Champion
November 23, 2022

Hi @Dmitry ,

Please enter plugin safe mode and check if issue still exists. If yes, please contact Atlassian support in https://support.atlassian.com/contact/

If no, enable one by one plugin and check if the issue is reproduced or not. Instead of enabling safe mode, you can check add-ons audit log, disable recently installed/upgraded add-ons and recheck for the issue. 

Dmitry
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
November 23, 2022

Thank you for answer

I can't recure error by my will and your variant will require a lot a time for check without plugins and working will be incomfortable
Between two repetition was a month

May be you have a idea - which a class of plugin can impact it?
I have not any plugin which working with login process

And error was as in portal JSM as in JS inreface.

Rilwan Ahmed
Community Champion
November 24, 2022

Hi @Dmitry ,

I have no idea which plugin would cause the issue. 

As said earlier, please reproduce the issue, collect the support zip and contact the Atlassian support

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events