JIRA/Confluence cloud addon security

Greg Hubbard September 19, 2017

I am assessing an addon to our JIRA/Confluence cloud instance. In the marketplace under 'Integration Details' There is the following statement:

'xxxxx for JIRA integrates with your Atlassian product. This remote service can:

  • Administer the host application
  • Administer Confluence spaces
  • Administer JIRA projects
  • Delete data from the host application
  • Write data to the host application
  • Read data from the host application'

That would appear to be giving full access to all of our Confluence and JIRA data to a third party. 

However, looking at an existing plugin that we have installed, it has added a system user and has placed that system user in the jira_software_users group.

And I correct that a plugin can be limited in the data it can access in our instance by securing spaces and projects to only allow access to users with additional groups above the basic jira_software_users group? 

Or do plugins get access to all our data?

1 answer

0 votes
Shannon S
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
September 21, 2017

Hello Greg,

The modification you mention would, in theory, work, however, it could break many add-ons if they require administrative level access. 

My recommendation would be to reach out to the vendor in question regarding which add-ons you're most concerned about. 

Let me know if you have any trouble determining that!

Kind Regards,
Shannon

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events