Hi,
The login procedure for managed users contains a dangerous security issue.
Steps:
- The managed user wants to use the Confluence/Jira site of the company
- The user does not remember the exact URL of the site and performs a search
- The user clicks on one of the search results and selects one of the buttons "Get Confluence", "Get Jira", etc...
- The users enters their work email and uses the identity provider login (IDP)
- The user gets logged in through the IDP
Expected results:
- Atlassian knows that the user is a managed user that belongs to an organization
- The organization has already one or more EXISTING sites
- Atlassian should redirect the user to a page offering a choice between the EXISTING sites
Actual results:
- The user is redirected to a signup page which also contains a "welcome back" message, tricking the user into thinking they are on the right track
- The page contains a prefilled edit box with a site name that contains the organization name.
- Because the site name contains the organization name, the user thinks he is still on the right track and clicks the blue button
- In the next step a NEW organization and a NEW site are created
- The user is still not aware that he is working outside of the organization and can start entering confidential company data into this new site This security issue requires urgent fixing.
Proposal:
- A managed user of an organization should not be allowed to create new sites
- Only organization admins are allowed to create new sites
Thanks,
Stefaan