Is the Issue Collector a (security) risk Edited

Hi,

we have a public JIRA instance that is used by our customers to report bugs directly. Now we want to implement a feedback function in our windows-software and want to use the issue-collector feature to do so.

By analyzing the issue collector functionality, we've noticed that there is no captcha, login, obviouscation or other feature that prevents users from "spamming" the public available interface to create plenty of entries in JIRA.

One you have the URL (by sniffing or using a proxy) you can simple "denial of service" JIRA by creating thousands or more JIRA tickets through the public interface.

 

Is there anything we're missing that Atlassian has done to prevent that kind of attack?

0 answers

Suggest an answer

Log in or Sign up to answer
How to earn badges on the Atlassian Community

How to earn badges on the Atlassian Community

Badges are a great way to show off community activity, whether you’re a newbie or a Champion.

Learn more
Community showcase
Published 8 hours ago in Off-topic

Get to know our Atlassian User Group Leaders from Bengaluru, India

Meet @Dinesh Dhinakaran, @Vishnu Vasudeva, @Rajeev Verma, and Jamshid Nalakath: Our extraordinary AUG leaders from Bengaluru, India. These four work together to strengthen the bonds of their local co...

82 views 0 4
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you