It's not the same without you

Join the community to find out what other Atlassian users are discussing, debating and creating.

Atlassian Community Hero Image Collage

Is the Issue Collector a (security) risk Edited

Hi,

we have a public JIRA instance that is used by our customers to report bugs directly. Now we want to implement a feedback function in our windows-software and want to use the issue-collector feature to do so.

By analyzing the issue collector functionality, we've noticed that there is no captcha, login, obviouscation or other feature that prevents users from "spamming" the public available interface to create plenty of entries in JIRA.

One you have the URL (by sniffing or using a proxy) you can simple "denial of service" JIRA by creating thousands or more JIRA tickets through the public interface.

 

Is there anything we're missing that Atlassian has done to prevent that kind of attack?

2 answers

Hi All,

there is a brand new App called "ReVitalized Issue Collector for Jira" in Atlassian Marketplace, it adds the  Google reCAPTCHA feature for better security and anti spam to any existing issue collector.

And in addition you can style the Form with your own CSS.


https://marketplace.atlassian.com/apps/1221494/revitalized-issue-collector-for-jira?hosting=server&tab=overview

Cheers
Heiko

Suggest an answer

Log in or Sign up to answer
TAGS

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you