Unauthenticated access to entire Jira

ITSecA I'm New Here Nov 30, 2017

Hi all

After upgrade to the latest version of Jira Core 7.6.0 i found a strange behavior. I have Jira in private mode. If i access the logon page i see the top bar (includes Project). Click on projects and select view all projects. This provides me a list which i can access and read all documents without any authentication. I am not sure if this is a bug or any miss-configuration at all.

Does someone face the same issue or can point me to a configuration where this is not possible?

 

Thank you all very much for Feedback

Sascha

1 answer

1 votes

Your project permissions schemes have "Browse project: anyone" in them

ITSecA I'm New Here Nov 30, 2017

Dear Nic

Thank you very much for your help. Thought I set this once but I it seems I overlooked it. In any case it worked. Thank you very much.

Suggest an answer

Log in or Join to answer
Community showcase
Teodora [Botron]
Published Thursday in Marketplace Apps

Jira Inferno: The Nine Circles of Jira Administration Hell

If you spend enough time as a Jira admin - whether you are managing a single, mid-sized instance, a large enterprise one or juggling multiple instances at once - you will eventually find yourself in ...

269 views 0 12
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you
Atlassian Team Tour

Join us on the Team Tour

We're bringing product updates and pro tips on teamwork to ten cities around the world.

Save your spot