Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Critical Security vulnerability - Password are not encripted and display in URL

Claude Cuttaia May 4, 2023

I was really badly surprise to see my password display in the URL when i click on Bitbucket from JIRA or Confluence.

https://bitbucket.org/my-atlassian-passord-in-clear/workspace/overview

 

that means my password is not encripted,  can be found by a lot of people, is very vulnerable due to this bug and Atlassian expose it without taking the minimum of security mesure. 

Atlassian  password.JPG

Can you share if you have the same vulnerability ?

1 answer

1 accepted

1 vote
Answer accepted
Oliver Siebenmarck _Polymetis Apps_
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
May 4, 2023

Hi @Claude Cuttaia ,

Welcome to the community!

That is indeed very peculiar. Usually that part of the URL should be the name of the workspace you are in or your username, it should never be your actual password (unless they are identical). 

So, if you can confirm that your password is being leaked here, I would suggest contacting Atlassian directly, you can report a vulnerability here: https://www.atlassian.com/trust/security/report-a-vulnerability

Best regards,
 Oliver

Claude Cuttaia May 4, 2023

Thanks you Oliver for your answer,

I confirm that it is my password in plain text and that it is different than my account name and user name, so I contacted support.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PERMISSIONS LEVEL
Site Admin
TAGS
AUG Leaders

Atlassian Community Events