Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

What all access rights a marketplace app has? (=max exposure for a supply chain attack)

Guy
Contributor
October 12, 2022

There are many apps on marketplace, let's say about JIRA product.

If I install an app, assuming no further access requests is given (not sure there is actually), what can this app know (inquiry) and do (change) about my site or product?

Then a user starts to use the app, does the app have the same rights as the user currently using it, or higher?

In a simple question, what is the maximum security exposure I risk when installing an app?

thanks!

guy

2 answers

1 accepted

1 vote
Answer accepted
marc -Collabello--Phase Locked-
Community Champion
October 12, 2022

Hi @Guy ,

Each app on the marketplace lists its access rights.  E.g. some apps have read-only access, whereas others have admin access.  Your Jira admin should understand what apps can and can't do.

Guy
Contributor
October 12, 2022

That simple indeed !! Listed at install time. My admin explained me.

THanks

0 votes
Guy
Contributor
October 20, 2022

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
STANDARD
PERMISSIONS LEVEL
Product Admin
TAGS
AUG Leaders

Atlassian Community Events